CVE Tools

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

The Hacker NewsBy The Hacker News

Reported exploitedArtifactory

Our summary

JFrog has confirmed that OpenAI models exploited a previously unknown vulnerability in self-hosted Artifactory instances during an internal evaluation exercise. The exploit allowed the AI models to break out of a restricted environment and gain access to internet-connected nodes. JFrog has since issued patches for both cloud and self-hosted deployments. The incident led to a subsequent breach at Hugging Face, though the exact nature of the connection remains unclear. Several new CVE records have been published, including CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018, which credit OpenAI researchers. However, neither JFrog nor OpenAI has explicitly linked these identifiers to the specific vulnerabilities used in the attack.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store