JFrog is a software company known for DevOps and software supply chain security tooling (e.g., Artifactory, Xray).
Overview
JFrog is a software company known for DevOps and software supply chain security tooling (e.g., Artifactory, Xray). It has gained prominence in cybersecurity for its work identifying and disclosing high-severity vulnerabilities in widely used software components—most notably the React JavaScript library—that threaten software supply chains and could impact millions of developers.
Related Threat Clusters
-
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request…
40 articles · Updated September 2, 2026 -
Critical FFmpeg Vulnerability Enables Remote Code Execution via Malicious Media Files
A critical vulnerability in FFmpeg's MagicYUV decoder, tracked as CVE-2026-8461, allows attackers to exploit heap out-of-bounds writes to crash systems or execute remote code. Discovered by JFrog, the flaw affects a…
9 articles · Updated June 23, 2026 -
Critical JFrog Artifactory CVE-2026-82329 Under Active Exploitation
A critical vulnerability, CVE-2026-82329, in JFrog Artifactory has been disclosed with a CVSS score of 9.8. Attackers can exploit this flaw without authentication, allowing them to mint admin tokens and potentially…
2 articles · Updated September 1, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
JFrog Discovers Critical React Vulnerability in Software Supply Chains
JFrog has identified a critical vulnerability in React, rated CVSS 9.8, which allows unauthenticated attackers to execute arbitrary operating system commands on affected machines. This vulnerability poses a significant…
2 articles · Updated November 6, 2025 -
Gainsight Apps Breach Exposes Data of Over 200 Salesforce Customers
A significant supply chain attack has compromised Salesforce-stored data from more than 200 companies through applications published by Gainsight. Salesforce confirmed unauthorized access to customer data and is…
30 articles · Updated November 23, 2025 -
Hackers Exploit React Native Metro Vulnerability to Target Developers
Hackers are exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native, affecting developers on Windows, Linux, and macOS. The vulnerability allows unauthenticated attackers to execute…
14 articles · Updated February 3, 2026 -
Critical Vulnerabilities in n8n Workflow Automation Platform Disclosed
Multiple critical vulnerabilities in the n8n open-source workflow automation platform were disclosed, allowing authenticated users to execute remote code on the server. These vulnerabilities, tracked as CVE-2026-25049,…
61 articles · Updated February 4, 2026 -
OpenAI Launches GPT-5.4-Cyber Amidst Cybersecurity Arms Race
OpenAI has introduced GPT-5.4-Cyber, a specialized AI model for defensive cybersecurity, available only to vetted professionals through its Trusted Access for Cyber (TAC) program. This model is designed to facilitate…
1370 articles · Updated April 14, 2026 -
Critical React Vulnerability Discovered by JFrog Threatens Software Supply Chains
JFrog has identified a critical vulnerability in React, rated CVSS 9.8, which allows unauthenticated attackers to execute arbitrary operating system commands on affected machines. This vulnerability poses a significant…
2 articles · Updated November 6, 2025
Recent Intelligence Reports
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners — Thehackernews · September 3, 2026
- Another Artifactory CVE under attack by AI agents or humans — Theregister · September 1, 2026
- Elon Musk Warns AI Hacking Will Go Superhuman by End of 2027 | Editor's Pick AI News — Cryptorank · August 31, 2026
- AI slop pollutes the CVE pipeline with fake vulns — Theregister · August 3, 2026
- AI-Driven Exploitation of JFrog Artifactory Zero — Rescana · July 29, 2026
- OpenAI agent chained JFrog zero-day into Hugging Face hack — Aiweekly.Co · July 29, 2026
- JFrog Patches Artifactory Zero — Gbhackers · July 29, 2026
- JFrog discloses zero — Cryptobriefing · July 29, 2026