JFrog is a organization tracked across 11 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity June 24, 2026.
JFrog is a software company known for DevOps and software supply chain security tooling (e.g., Artifactory, Xray). It has gained prominence in cybersecurity for its work identifying and disclosing high-severity vulnerabilities in widely used software components—most notably the React JavaScript library—that threaten software supply chains and could impact millions of developers.
A critical vulnerability in FFmpeg's MagicYUV decoder, tracked as CVE-2026-8461, allows attackers to exploit heap out-of-bounds writes to crash systems or execute remote code. Discovered by JFrog, the flaw affects a…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
JFrog has identified a critical vulnerability in React, rated CVSS 9.8, which allows unauthenticated attackers to execute arbitrary operating system commands on affected machines. This vulnerability poses a significant…
A significant supply chain attack has compromised Salesforce-stored data from more than 200 companies through applications published by Gainsight. Salesforce confirmed unauthorized access to customer data and is…
Hackers are exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native, affecting developers on Windows, Linux, and macOS. The vulnerability allows unauthenticated attackers to execute…
Multiple critical vulnerabilities in the n8n open-source workflow automation platform were disclosed, allowing authenticated users to execute remote code on the server. These vulnerabilities, tracked as CVE-2026-25049,…
JFrog has identified a critical vulnerability in the React framework, rated CVSS 9.8, which allows unauthenticated attackers to execute arbitrary operating system commands on affected machines. This vulnerability poses…
JFrog has identified a critical vulnerability in React, rated CVSS 9.8, which allows unauthenticated attackers to execute arbitrary operating system commands on affected machines. This vulnerability poses a significant…
Hackers compromised Salesforce-stored data from more than 200 companies through a supply chain attack involving Gainsight applications. Google confirmed the breach, stating that unauthorized access to customer data was…
Thousands of credentials, authentication keys, and configuration data from banks, government, and tech organizations were found in publicly accessible JSON snippets submitted to the JSONFormatter and CodeBeautify tools.…