CVE-2026-70548: JFrog Artifactory

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.

Affected products

  • JFrog Artifactory: from 7.161.11, before 7.161.19 (fixed in 7.161.19); from 7.146.0, before 7.146.36 (fixed in 7.146.36)

Published 2026-08-25. Last modified 2026-08-28.