Column 1
Skip to content

JFrog Artifactory CVE-2026-66384 KEV: Patch Self-Hosted Repositories

August 27, 2026

CISA added JFrog Artifactory CVE-2026-66384 to its Known Exploited Vulnerabilities catalog on August 27, 2026. If you run self-hosted Artifactory, use the vendor’s fixed supported release for your installed branch. The published fixed releases are 7.146.35 and 7.161.16. Treat this as a focused maintenance task: identify exposed instances, use your approved update process, review trusted access, and verify the repository and build workflows your team relies on.

Self-hosted artifact repository packages beside a protected server rack during a security update

This is a defensive maintenance guide. It intentionally avoids technical attack detail and focuses on safe patching and operational verification.

Who should act now

  • Organizations running self-hosted JFrog Artifactory for software packages, build dependencies, containers, or internal repositories.
  • Teams with Artifactory reachable from the internet, a corporate network, or a shared development environment.
  • Hosting and platform administrators responsible for the server, its reverse proxy, storage, and repository access.

Update Artifactory safely

  1. Identify every Artifactory instance, its installed version, operating system, service account, storage dependencies, and normal maintenance owner.
  2. Use the vendor-supported update path already approved for that deployment. Do not change a backup schedule solely for this update.
  3. Update to 7.146.35 or 7.161.16, according to the supported branch that applies to your deployment. Prefer the current supported vendor release when it fits your normal compatibility and change-control process.
  4. Review public exposure and limit administrative access to trusted networks and people wherever your operating model permits.
  5. Confirm that repository, token, automation, and administrator permissions still follow least privilege after maintenance.

Verify normal service after the update

  • Confirm the running Artifactory version in the administration area or your normal service inventory.
  • Check the expected Artifactory web sign-in and authorized administrator access.
  • Use an approved account to confirm representative package retrieval, repository browsing, and expected build or integration status.
  • Review ordinary service health, application logs, monitoring, and support channels for unexpected errors after the change.
  • Record the release installed, maintenance window, owner, and verification results for the environment.

Related hosting guidance

Administrators maintaining related hosting services can also use the WHM and cPanel hub. For a virtual-machine maintenance plan, start with the Proxmox hub. Teams that need help coordinating WordPress and hosting maintenance can start with WordPress support.

Sources