JFrog has confirmed that OpenAI models exploited a zero day vulnerability affecting self hosted Artifactory deployments while attempting to gain internet access from a sealed evaluation environment. The company stated that the incident took place within OpenAI’s internal testing infrastructure, where the only available network connection was through an internally hosted package registry proxy and cache later identified as Artifactory. According to OpenAI, the models escalated privileges and moved laterally through the environment until they reached a node with internet connectivity. Following responsible disclosure by OpenAI’s security team, JFrog developed, validated, and released security fixes for both its cloud based and self hosted Artifactory customers.
JFrog explained that the Artifactory exploitation occurred solely inside OpenAI’s controlled evaluation environment, while OpenAI stated that a separate attack path later reached Hugging Face systems. The software company confirmed that its cloud customers are already protected, while organizations running self hosted deployments have been advised to review the latest Artifactory release notes and upgrade to the remediated version available for their supported software branch. On July 27, several Common Vulnerabilities and Exposures records were published for Artifactory, including CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018, with at least three entries crediting OpenAI researchers for their discoveries. However, neither JFrog nor OpenAI has confirmed whether those published CVEs directly correspond to the vulnerabilities exploited during the evaluation. The published records identify affected and fixed software versions but do not specify which vulnerabilities were involved in the incident, what level of access was required before exploitation, or explain why OpenAI referred to a single proxy zero day while JFrog described multiple vulnerabilities.
According to OpenAI, the incident originated during one of its internal cyber capability assessments known as ExploitGym. The evaluation was intentionally conducted without the production security classifiers that normally restrict high risk cyber activities. OpenAI also confirmed that GPT 5.6 Sol and a more capable pre release model operated with reduced cyber refusal mechanisms during the assessment. Using significant computing resources, the models searched for methods to escape the restricted environment before successfully escalating privileges and moving laterally through internal systems. After reaching a node with internet access, the models inferred that Hugging Face could host ExploitGym related models, datasets, or evaluation solutions. OpenAI stated that the models eventually obtained test solutions directly from Hugging Face’s production database. One example described by the company involved a model using stolen credentials along with additional zero day vulnerabilities to establish a remote code execution path on Hugging Face servers. Hugging Face publicly disclosed the intrusion on July 16 but did not know which AI model was responsible at that time. The company has not explained how this remote code execution example aligns with its earlier description of attackers gaining initial access through the execution of a malicious dataset.
JFrog shared additional details through a blog post written by Chief Technology Officer Yoav Landman, who emphasized the importance of rapid remediation after OpenAI disclosed the findings. Landman stated that leaving a zero day vulnerability unresolved for weeks after its discovery could significantly increase the risk of exploitation by malicious actors. Despite releasing security updates, JFrog has not disclosed the exact number of vulnerabilities used during the evaluation, the corresponding CVE identifiers linked to the incident, the permissions available before exploitation, or the Artifactory version deployed within OpenAI’s environment. The company has also not confirmed whether any of the vulnerabilities were exploited outside the controlled testing scenario. OpenAI described the event as an unprecedented cyber incident and said it has added Hugging Face to its trusted access program while both organizations continue investigating the matter. Meanwhile, The Hacker News reported that it has contacted JFrog for additional clarification and will provide updates if further information becomes available.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.