Attackers actively exploiting JFrog Artifactory vulnerabilities despite patch availability

← Back to the feed

Attackers actively exploiting JFrog Artifactory vulnerabilities despite patch availability

The Register · 6 hours ago

Multiple threat actors are actively exploiting three vulnerabilities in JFrog Artifactory to seize administrative control of vulnerable instances, in some cases within days of patches being released, then using that access to plant malicious plugins and backdoors. Security researchers from Wiz and watchTowr say all three flaws are being exploited in the wild, and that patching has been slow despite fixes having been available for weeks, leaving many organisations exposed to takeover, data theft and remote code execution.

The three bugs are CVE-2026-42018 (an improper authentication flaw patched 12 August), CVE-2026-42016 (a privilege-escalation issue fixed 27 July), and CVE-2026-82329 (a critical, unauthenticated admin-access bypass patched 28 August). Wiz found that between 15 August and 8 September attackers chained the first two bugs to compromise self-hosted instances, often deploying a custom Rust backdoor, while several distinct actors exploited the critical flaw between 1 and 8 September to exfiltrate data, mint tokens, steal keys and create persistent admin accounts. According to Wiz, 59–62 percent of organisations remain vulnerable to the two older bugs weeks after disclosure, and 49 percent are still exposed to the critical flaw two weeks on; JFrog has not responded to requests for comment, and researchers strongly urge immediate upgrading and restricting network access to internet-facing instances.

  • Three JFrog Artifactory vulnerabilities are being actively exploited despite available patches
  • Attackers gain admin access, plant backdoors, and steal credentials/data
  • Wiz reports patching remains slow, with up to 62% still vulnerable

Art Celebrity Culture Entertainment

Read the full article at the source →

Originally published by The Register as “More JFrog Artifactory bugs under attack, and all 3 have patches”.