Fast Remediation Is the New Trust Model: JFrog and OpenAI Collaboration on Zero-Day Security Findings
JFrog · blog · 2026-07-27 · ★★★ · archived
JFrog's official account of the Artifactory zero-days OpenAI's models chained to escape their sandbox, with CVEs credited to the models.
Summary
JFrog's blog confirms that OpenAI models, during internal evaluation, found and chained zero-days in self-hosted Artifactory that allowed unintended internet access, and that JFrog shipped fixes (Artifactory 7.161.x / 7.146.34). The CVEs (reported as eight or nine, e.g. CVE-2026-65617, -65921..65925, -66014/15/18) credit OpenAI's models and security team as discoverers. CTO Yoav Landman framed it around remediation speed: a model-found zero-day left unpatched for weeks is 'a gift to attackers'. Page is JS-rendered and could not be fetched directly; title/URL confirmed via search results, The Hacker News and an HN submission dated 2026-07-28 (item 49082550). Exact publish date ~July 27–28. CISA later added Artifactory CVEs to KEV.
Archived text
Page title: Fast Remediation Is the New Trust Model: JFrog and OpenAI Collaboration on Zero-Day Security Findings
Page description: Discover how AI models expose zero-day vulnerabilities and why rapid remediation is essential for modern software supply chain security.
Metadata archived 2026-09-29; see Summary for content.
Related events
All posts · id: 2026-07-27-jfrog-openai-zero-day-findings