JFrog vendor intelligence
JFrog Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting JFrog products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 3
- Known exploited vulnerabilities affecting JFrog products
- In CISA KEV
- 1
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- JFrog KEVs with sensor-observed exploitation activity
The catalog gap matters for JFrog exposure
Two of the three exploited JFrog vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss two-thirds of this vendor portfolio.
- 33%
- Covered by CISA
- 67%
- Beyond CISA
- 2
- Product families
Attested JFrog vulnerabilities
3 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-82329
Potential authentication bypass leading to administrative access in Artifactory |
artifactory | High | Beyond CISA | 01 Sep 2026 |
|
CVE-2026-66384
Authenticated users may write data outside the intended Docker cache path |
artifactory | Confirmed | In CISA | 27 Aug 2026 |
|
CVE-2019-9733
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case... |
Artifactory | High | Beyond CISA | 28 Jun 2025 |
No JFrog vulnerabilities match this search or filter.
Showing 3 of 3 JFrog known exploited vulnerabilities.
Recurring weakness patterns
Limitation and authentication account for two mapped occurrences across this JFrog KEV portfolio.