VDB
GCVE-110-BRLY-2026-016
GCVE-110-BRLY-2026-016
Advisory Published
BRLY-2026-016 Critical BINARLY REsearch team identified an exposed JFrog Artifactory reference token embedded in container images hosted on Docker Hub under the `ciscosecurity` namespace. The token is configured as an HTTP Basic authentication credential for a private PyPI registry. An attacker with access to a valid token could download proprietary Python packages from Cisco's internal XDR data pipeline registry, and potentially upload malicious packages to conduct a supply chain attack against Cisco's XDR platform.
References
Browse GCVE Records
556 records in the GCVE database · Updated September 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.