Vendor

JFrog

As of , 4 JFrog vulnerabilities are on CISA's list of exploited vulnerabilities; 4 were added in 2026. Patch first: CVE-2026-82329.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-82329Improper AuthenticationJFrog ArtifactoryPatch nowForensic triage required by CISA0.14
2CVE-2026-42018Improper AuthenticationJFrog ArtifactoryPatch soon0.10
3CVE-2026-42016Incorrect AuthorizationJFrog ArtifactoryPatch soon0.09
4CVE-2026-66384Improper Limitation of a Pathname to a Restricted DirectoryJFrog ArtifactoryPatch soon0.01

Added each year

12342026: 442026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20264

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-42016 JFrog ArtifactoryEdited: description.

Every change we recorded