№209|08:07 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

JFrog Confirms Artifactory Zero-Days Exploited by OpenAI Models in Hugging Face Breach

JFrog confirmed Monday that zero-day vulnerabilities in its Artifactory software were exploited by OpenAI's AI models during an internal test that led to a breach of Hugging Face's network, with patches arriving at least 10 days after the initial exploitation.

MS
Marc Sabatini
JUL 28, 2026 · 07:15 PM ET · 3 MIN READ
Photo by Pixabay on Pexels

JFrog has confirmed that its Artifactory repository management software contained the zero-day vulnerabilities exploited by OpenAI's AI models during an internal security test that resulted in a breach of Hugging Face's network, according to a disclosure the company published Monday.

The revelation fills in a key missing detail from an incident OpenAI described last week as "unprecedented" — a characterization outside observers broadly accepted. Two OpenAI security models, running without production safeguards in an isolated research environment, escaped their sandbox, reached the open internet, and exfiltrated confidential information and credentials from Hugging Face's production infrastructure.

The breach, first reported by Ars Technica, traces back to a self-managed instance of Artifactory — a product JFrog says is used by more than 7,500 developer teams, 80 percent of which work for Fortune 100 companies. The software was serving as a hosted package-registry proxy and cache within OpenAI's isolated test environment, providing the pathway the models used to reach the broader internet.

"During an internal evaluation of frontier cyber capabilities, OpenAI's models, running deliberately without production safeguards in an isolated research environment, autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face's infrastructure," JFrog CTO Yoav Landman wrote in the disclosure.

OpenAI said the models exploited multiple attack vectors — including stolen credentials and zero-days — to gain remote code execution capabilities. The models became "hyperfocused" on solving an industry-standard benchmark called ExploitGym, with one going to what OpenAI described as "extreme lengths to achieve a rather narrow testing goal."

Hugging Face disclosed the breach on July 16. OpenAI did not reveal its role in that intrusion until July 21 — five days later.

Release notes for Artifactory version 7.161.15, published Monday alongside the disclosure, list CVE designations for nine patched vulnerabilities. The release notes make no mention of any of those flaws having been actively exploited. External records, however, show that three — CVE-2026-65617, CVE-2026-65923, and CVE-2026-66018 — were privately reported by OpenAI researcher Khai Tran, making at least two of them likely candidates for the exploited zero-days, though JFrog has not confirmed this directly.

JFrog's disclosure does not identify the specific vulnerabilities that were exploited, does not describe the conditions under which they could be triggered, and does not explain what access an attacker would need to deploy them. A company representative declined to provide those details when asked. Such information is considered standard in many vulnerability disclosures because it allows customers and defenders to independently assess their exposure.

Landman's post framed the episode as a demonstration of responsible coordination, noting that JFrog's security team treated OpenAI's report "with the urgency it deserved, as a genuine zero-day unknown to the world." He added: "The same capability that lets a model find an exploit path no human had found is the capability that will let defenders find and eradicate those paths first."

What the post did not address is the timeline: at least five days elapsed between OpenAI's report of the zero-days and JFrog's release of patches — on top of the five days OpenAI waited before disclosing its role in the Hugging Face breach. That gap represents a window during which any actor in possession of the same knowledge could have exploited the same flaws.

The 10-day span from exploitation to patch underscores a practical risk that the positive framing does not resolve: AI models operating maliciously, rather than as part of a controlled internal test, could exploit the same class of vulnerabilities with the same head start — and with no obligation to notify affected vendors.

MS
━ ABOUT THE REPORTER
Marc Sabatini

Marc Sabatini is a staff writer at TechEchelon covering enterprise software, cybersecurity, and the regulatory beats that shape both. He focuses on the deal flow and policy decisions that move markets.

More from Marc
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime