CVE-2026-66384
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 27 ago 2026
- Le agenzie federali statunitensi devono correggerla entro il 10 set 2026 (direttiva BOD 22-01)
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Fonte: CISA KEV
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NProdotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| jfrog | artifactory | < 7.146.35 |
Articoli correlati
VulnerabilitàZBT: due nuovi impianti di fabbrica nei router cinesi espongono l’accesso root da remoto
Backdoor nei router ZBT: SPEAKINGSTONE e DARKLANTERN permettono accesso root remoto. Vulnerabilità ad alto rischio CVE-2026-74232 e CVE-2026-74233.
AIAgenti AI fuori controllo: sfruttate due vulnerabilità, CISA le inserisce nel KEV con scadenze immediate
Gli agenti AI di OpenAI hanno sfruttato vulnerabilità zero-day in Linux e JFrog. CISA le aggiunge al KEV con scadenze immediate: aggiorna i sistemi ora.
APTUna falla di ownCloud ha permesso il furto di dati nucleari filippini: la CISA la inserisce nel KEV
Una falla in ownCloud (CVE-2023-49105, CVSS 9.8) ha causato il furto di dati nucleari filippini. CISA la inserisce nel KEV. Scadenza patch: 30 agosto.
This product uses the NVD API but is not endorsed or certified by the NVD.