CVE-2026-66016: JFrog Artifactory

Medium severity, CVSS 6.7. EPSS: 0.1% chance of exploitation in the next 30 days.

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.

Affected products

  • JFrog Artifactory: before 7.146.35 (fixed in 7.146.35); from 7.161.0, before 7.161.16 (fixed in 7.161.16)

Published 2026-08-12. Last modified 2026-09-11.