A 9.8 Critical CVE That Never Existed: How to Filter Fake Vulnerabilities Out of Your Java Pipeline
JFrog's security team exposed a wave of fabricated SQLite vulnerability advisories, including a fake CVE-2026-51302 that was initially rated 10.0 critical, which had flowed through NVD, CISA, and Red …