CVE-2026-66018
published 2026-07-27CVE-2026-66018: Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.43%
36.2th percentile
Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no integrity or availability impact demonstrated).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jfrog | artifactory | >= 7.146.0 < 7.146.34 | 7.146.34 |
| jfrog | artifactory | >= 7.161.0 < 7.161.15 | 7.161.15 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Recorded Future
The Hugging Face Hack Was Cheap Persistence at Work
blogs_recorded_future·2026-08-10
CVE-2026-65617 The Hugging Face Hack Was Cheap Persistence at Work
## The Hugging Face Hack Was Cheap Persistence at Work
The OpenAI-Hugging Face incident is being discussed primarily as a zero-day story. That framing is too narrow.
The agent discovered and exploited previously unknown vulnerabilities. The more consequential development came afterward. Over a four-and-a-half-day campaign, it carried out roughly 17,600 actions against Hugging Face’s infrastructure. Most of those actions failed. The operation advanced because each failure imposed little cost, and the next attempt could begin immediately. The system could keep exploring, reconstruct its tools, revisit abandoned paths, and test another hypothesis without fatigue or meaningful opportunity cost.
That changes both the economics and the tempo of cyber offense.
For most of cybersecurity histor
Hackernews
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
blogs_hackernews·2026-07-28·CVSS 6.5
CVE-2026-65618 [MEDIUM] JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.
Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud and self-hosted customers.
The Artifactory exploit occurred inside OpenAI's environment. OpenAI says a separate attack path later reached Hugging Fa
2026-07-27
Published