JFrog
Not listed by any tracked vendor.
Documents
| Document | Verified | Changed | Evidence |
|---|---|---|---|
| Trust center | snapshot | ||
| Subprocessor list | snapshot | ||
| Data processing addendum | snapshot | ||
| Privacy policy | snapshot | ||
| Terms | snapshot | ||
| security.txt | snapshot | ||
| Status page statuspage | snapshot | ||
| Security advisories | snapshot |
Subprocessors
11 third parties, 4 affiliates. CSV · Atom
| Name | Purpose | Location | Listed since |
|---|---|---|---|
| Amazon | Application AI Functionality. United States. | ||
| Amazon Web Services, Inc. (AWS) | Cloud Computing Services. Controllers can choose the location and region in accordance with the list available here.; Logs cloud hosting services. United States. | ||
| Anthropic | Application AI Functionality. United States. | ||
| Coralogix, Inc. | Log aggregation and correlation services. United States. | ||
| Application AI Functionality. United States. | |||
| Google Cloud Platform, LLC (GCP) | Cloud Computing Services. Controllers can choose the location and region in accordance with the list available here. | ||
| Mailgun Technologies, Inc. | Email notification services. United States. | ||
| Meta | Application AI Functionality. United States. | ||
| Microsoft | Application AI Functionality. United States. | ||
| Microsoft Azure, Corp. (Azure) | Cloud Computing Services. Controllers can choose the location and region in accordance with the list available here. | ||
| SendGrid (Twilio, Inc.) | Email notification services. United States. |
Security record
What public security catalogs list for JFrog, in their words.
Known exploited vulnerabilities
4 vulnerabilities in JFrog's software that CISA lists as exploited in the wild.
| CVE | Product | Vulnerability | Listed |
|---|---|---|---|
| CVE-2026-42016 | Artifactory | JFrog Artifactory Incorrect Authorization Vulnerability | evidence |
| CVE-2026-42018 | Artifactory | JFrog Artifactory Improper Authentication Vulnerability | evidence |
| CVE-2026-82329 | Artifactory | JFrog Artifactory Improper Authentication Vulnerability | evidence |
| CVE-2026-66384 | Artifactory | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | evidence |
Service status
1 incident in the last 4 days (0 major or critical, 0 minor, 1 with no stated impact)
| Began | Incident | Impact | Lasted |
|---|---|---|---|
| Potential UI bug for a subset of customers on JFrog Cloud Platform | none | — evidence |
As JFrog's status page reports its own incidents (scheduled maintenance left out), read every few hours since .
Changes
None since tracking began.