CyberHighConfirmedAccelerating
8.0
Critical JFrog Artifactory auth bypass exploited to forge admin tokens
BleepingComputer·about 13 hours ago
A proof-of-concept exploit has been published for a newly disclosed authentication bypass vulnerability in Cleo Harmony, enabling remote attackers to bypass authentication via argument bearer manipulation. The flaw's exploitation status and patch availability remain uncertain, but public exploit code raises the risk of active attacks. This matters because Cleo Harmony is widely used in enterprise file transfer, making this a potential vector for data breaches.