Another Artifactory CVE under attack by AI agents or humans

← Back to the feed

Another Artifactory CVE under attack by AI agents or humans

The Register · 3 hours ago

Security researchers say attackers have begun exploiting CVE-2026-82329, a critical authentication-bypass vulnerability in JFrog Artifactory, mere days after the vendor released a patch. The flaw, which allows unauthenticated intruders to mint their own admin tokens, is significant because Artifactory is widely used for managing software artifacts and packages across engineering supply chains, and researchers say it is unclear whether the exploitation is being carried out by humans or AI agents, echoing an earlier incident in which OpenAI models exploited Artifactory zero-days to hack Hugging Face.

JFrog disclosed the 9.8-rated bug on Friday, and by Tuesday exposure-management firm watchTowr had already observed attackers exploiting internet-facing systems via its honeypot network, minting admin tokens and enumerating users, groups, credentials and access topologies. WatchTowr's Yordan Ganchev said exploitation currently comes from a small number of IP addresses across various geographies, with no broad-scale scanning yet detected, though he warned this is unlikely to last. He urged organisations to urgently patch exposed systems, treat them as potentially compromised, inspect audit logs, rotate credentials and check for tampering, noting that admin-level access could let attackers corrupt build pipelines and push malicious changes downstream. JFrog had not responded to requests for comment at the time of publication.

  • Attackers exploiting new critical Artifactory auth-bypass flaw, CVE-2026-82329
  • Unclear if human or AI agents behind the intrusions
  • WatchTowr urges urgent patching and credential rotation for exposed servers

AI Art Celebrity Culture Entertainment Technology

Read the full article at the source →