JFrog Artifactory CVE-2026-66384 KEV: Patch Self-Hosted Repositories
August 27, 2026
CISA added JFrog Artifactory CVE-2026-66384 to its Known Exploited Vulnerabilities catalog on August 27, 2026. If you run self-hosted Artifactory, use the vendor’s fixed supported release for your installed branch. The published fixed releases are 7.146.35 and 7.161.16. Treat this as a focused maintenance task: identify exposed instances, use your approved update process, review trusted access, and verify the repository and build workflows your team relies on.

This is a defensive maintenance guide. It intentionally avoids technical attack detail and focuses on safe patching and operational verification.
Who should act now
- Organizations running self-hosted JFrog Artifactory for software packages, build dependencies, containers, or internal repositories.
- Teams with Artifactory reachable from the internet, a corporate network, or a shared development environment.
- Hosting and platform administrators responsible for the server, its reverse proxy, storage, and repository access.
Update Artifactory safely
- Identify every Artifactory instance, its installed version, operating system, service account, storage dependencies, and normal maintenance owner.
- Use the vendor-supported update path already approved for that deployment. Do not change a backup schedule solely for this update.
- Update to 7.146.35 or 7.161.16, according to the supported branch that applies to your deployment. Prefer the current supported vendor release when it fits your normal compatibility and change-control process.
- Review public exposure and limit administrative access to trusted networks and people wherever your operating model permits.
- Confirm that repository, token, automation, and administrator permissions still follow least privilege after maintenance.
Verify normal service after the update
- Confirm the running Artifactory version in the administration area or your normal service inventory.
- Check the expected Artifactory web sign-in and authorized administrator access.
- Use an approved account to confirm representative package retrieval, repository browsing, and expected build or integration status.
- Review ordinary service health, application logs, monitoring, and support channels for unexpected errors after the change.
- Record the release installed, maintenance window, owner, and verification results for the environment.
Related hosting guidance
Administrators maintaining related hosting services can also use the WHM and cPanel hub. For a virtual-machine maintenance plan, start with the Proxmox hub. Teams that need help coordinating WordPress and hosting maintenance can start with WordPress support.

