CISA has added CVE-2026-66384 to its Known Exploited Vulnerabilities catalogue. The affected vendor is JFrog and the product is Artifactory. The vulnerability, named “JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability”, allows an authenticated user to write data outside the intended Docker cache path under specific remote‑repository conditions.
The flaw is a pathname‑traversal issue that enables an authenticated attacker to bypass directory restrictions and write arbitrary files via the Docker cache mechanism. It is rated CVSS 5.3 (MEDIUM) and can lead to unauthorized file creation or modification on the affected system. Exploitation requires network access and a valid user account. A patch is available from JFrog, and administrators should apply the update as soon as possible.
CISA confirms that this vulnerability is being actively exploited in the wild. No known ransomware campaign has been linked to CVE‑2026-66384 at this time. Federal civilian executive branch (FCEB) agencies must remediate the issue by the CISA‑specified due date of 10 September 2026.
CISA’s required action is: “Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.
Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines.” While this directive binds FCEB agencies, all organisations should review their exposure to JFrog Artifactory and implement the vendor’s mitigations or updates promptly.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-66384 and the CISA KEV catalogue.