Security analysts discovered active in-the-wild attacks targeting three JFrog Artifactory vulnerabilities. Threat actors chain these flaws to bypass authentication checks and obtain full administrative control. Consequently, these intrusions allow unauthorized access to proprietary cloud artifacts, credentials, and build pipelines.
- Product: jfrog artifactory
- Vulnerabilities: 3 flaws (CVE-2026-82329, CVE-2026-42018, CVE-2026-42016)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Potential authentication bypass leading to administrative access in
- Status: Exploited in the wild
- Action: Update to 7.111.21, 7.117.28, 7.125.20, 7.133.29 (+8) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-82329 | 9.8 | CWE-287 | 7.111.21, 7.117.28, 7.125.20 (+3) | Exploited in the wild |
| CVE-2026-42016 | 8.1 | CWE-863 | 7.133.11 | Exploited in the wild |
| CVE-2026-42018 | 7.5 | CWE-287 | 7.111.20, 7.117.27, 7.125.19 (+2) | Exploited in the wild |
Why These Attacks Matter
JFrog Artifactory serves as a central repository manager for enterprise development teams. Telemetry estimates show that 67% of organizations running the software hosted at least one vulnerable instance during initial disclosures. Therefore, a compromise of this platform threatens the software supply chain directly. Intruders who breach Artifactory instances can tamper with binary builds and deploy unauthorized packages into production. Moreover, attackers use their administrative access to steal sensitive credentials and harvest repository data. This ongoing threat highlights the urgent risk facing self-hosted enterprise infrastructure.
How the Attacks Work
Threat actors exploit two distinct paths to compromise enterprise environments. In the first vector, attackers chain two vulnerabilities together to escalate their privileges. The report notes, “CVE-2026-42018 is an improper-authentication vulnerability that may cause Artifactory to return an internal anonymous-user token to an unauthenticated requester, even when anonymous access is disabled.”
Next, the attacker abuses the scope validation flaw tracked as CVE-2026-42016. According to the report, “Artifactory validates the token’s signature and issuer but does not properly enforce its intended scope.” Attackers exchange the low-privilege token for an admin-scoped token within minutes. In the second attack path, actors exploit CVE-2026-82329 directly. This flaw enables unauthenticated remote actors to request administrative tokens by calling specific registry endpoints.
Observed Post-Exploitation Activity
After gaining administrative control, threat actors deploy several persistent mechanisms. Intruders frequently create backdoor administrator accounts to maintain long-term access. Additionally, attackers upload malicious Groovy plugins to execute shell commands on host operating systems. Researchers also observed attackers installing custom Rust backdoors to establish command-and-control communication channels. Detailed technical findings appear in the official Wiz Research threat report.
Affected Versions
These JFrog Artifactory vulnerabilities impact multiple self-hosted release branches. Specifically, CVE-2026-82329 affects versions prior to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20. Similarly, CVE-2026-42018 impacts releases before 7.111.20 and 7.146.9. Furthermore, CVE-2026-42016 impacts all software builds prior to 7.133.11. Both Wiz Research and CISA have confirmed active exploitation in the wild. Public proof-of-concept exploit details are also accessible online.
Patch and Mitigation Steps
Administrators must apply vendor security updates immediately to protect their servers. JFrog released remediated releases across all supported software trains. Therefore, organizations should upgrade their instances to versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20. In addition, security teams must inspect audit logs for suspicious token minting requests. Restricting access to internal network perimeters provides additional defense against unauthenticated remote scans.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!