CVE-2026-66375: JFrog Artifactory
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
Affected products
- JFrog Artifactory: before 7.146.35 (fixed in 7.146.35); from 7.161.0, before 7.161.16 (fixed in 7.161.16)
Published 2026-08-12. Last modified 2026-09-02.