CVE-2026-65923
published 2026-07-27CVE-2026-65923: A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended…
PriorityP344medium6.8CVSS 3.1
AVNACHPRLUINSUCHIHAN
EPSS
0.34%
27.1th percentile
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests.
The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jfrog | artifactory | < 7.111.18 | 7.111.18 |
| jfrog | artifactory | >= 7.117.0 < 7.117.25 | 7.117.25 |
| jfrog | artifactory | >= 7.125.0 < 7.125.18 | 7.125.18 |
| jfrog | artifactory | >= 7.133.0 < 7.133.27 | 7.133.27 |
| jfrog | artifactory | >= 7.146.0 < 7.146.34 | 7.146.34 |
| jfrog | artifactory | >= 7.161.0 < 7.161.15 | 7.161.15 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Recorded Future
The Hugging Face Hack Was Cheap Persistence at Work
blogs_recorded_future·2026-08-10
CVE-2026-65617 The Hugging Face Hack Was Cheap Persistence at Work
## The Hugging Face Hack Was Cheap Persistence at Work
The OpenAI-Hugging Face incident is being discussed primarily as a zero-day story. That framing is too narrow.
The agent discovered and exploited previously unknown vulnerabilities. The more consequential development came afterward. Over a four-and-a-half-day campaign, it carried out roughly 17,600 actions against Hugging Face’s infrastructure. Most of those actions failed. The operation advanced because each failure imposed little cost, and the next attempt could begin immediately. The system could keep exploring, reconstruct its tools, revisit abandoned paths, and test another hypothesis without fatigue or meaningful opportunity cost.
That changes both the economics and the tempo of cyber offense.
For most of cybersecurity histor
Hackernews
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
blogs_hackernews·2026-07-28·CVSS 6.5
CVE-2026-65618 [MEDIUM] JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.
Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud and self-hosted customers.
The Artifactory exploit occurred inside OpenAI's environment. OpenAI says a separate attack path later reached Hugging Fa
2026-07-27
Published