VDB
GCVE-110-BRLY-2026-015
GCVE-110-BRLY-2026-015
Advisory Published
BRLY-2026-015 Critical BINARLY REsearch team identified multiple exposed JFrog Artifactory reference tokens embedded in container images hosted on Docker Hub under the `ciscosecurity` namespace. The tokens are configured as HTTP Basic authentication credentials for a private PyPI registry. An attacker with access to a valid token could download proprietary Python packages from Cisco's internal XDR data pipeline registry, and potentially upload malicious packages to conduct a supply chain attack against Cisco's XDR platform.
References
Browse GCVE Records
556 records in the GCVE database · Updated September 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.