
Security update: CVE-2026-90898 and CVE-2026-86242 are fixed in Bifrost v2.1.0
JFrog Security Research recently disclosed two vulnerabilities in Bifrost's management API. They can only be exploited when both of these are true: the instance is exposed to the internet, and dashboard authentication has not been set up. Both are fixed in transports/v2.1.0






















