וואלהגורם אמריקני: שגרירי ישראל ולבנון ייפגשו כדי לדון בהמשך יישום ההסכםCNN TürkHakkari'de ihale soruşturmasında 7 şüpheli tutuklandıESPN DeportesNecaxa arrastra cinco jornadas sin ganar antes de enfrentar a PueblaESPNPulisic 'upset' about Milan bench role, coach Amorim saysThe Jerusalem PostRosh Hashanah political quiz: What's going to happen in the Middle East in 5787?PunchAbia lauds driver for returning passenger’s N400,000UOLQuaest: aliados de Flávio lideram corrida ao governo em 9 Estados e no DF; de Lula, em 4SözcüAKP'ye geçince eşinin batık şirketi ihya oldu조선일보[오피셜]'끔찍한 교통사고→다리 뼈 산산조각→웨스트햄 방출→카타르 이적' 자메이카 국대 공격수 안토니오, 잉글랜드 2부 왓포드와 FA 계약..'6개월 만에 영국 컴백'The Hollywood ReporterPink Issues Statement Following Backlash for Critiquing Macklemore’s Pro-Palestine Comments: “Standing Up for My Own People”매일경제파킹형ETF에 1주새 1.5조 몰려...안전한 금융상품 선호NOSZuid-Korea meldt afvuren ballistische raketten richting zee door Noord-Korea
The Daily Newsstand · Free, Always
Saturday, September 12, 2026

More JFrog Artifactory bugs under attack, and all 3 have patches

Translate

If you're waiting for a sign to upgrade to a fixed version: this is it

JFrog Artifactory instances continue to get hit hard. Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over vulnerable instances - in some cases, just days after the vendor published a patch - and then using this illicit access to install malicious plugins and backdoors.

The three vulnerabilities are:

CVE-2026-42018 is a high-severity, improper authentication flaw that can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled. An attacker can use this token to authenticate to the repository manager and then access sensitive resources. JFrog patched this vulnerability on August 12.

REG AD

CVE-2026-42016 is a high-severity privilege-escalation bug. Artifactory doesn’t properly validate the token’s scope, and this can allow an attacker with low-privileged access to elevate privileges and perform actions that they should not be allowed to do. JFrog fixed this one on July 27.

REG AD

CVE-2026-82329 is a critical authentication-bypass vulnerability that allows unauthenticated attackers with network access to obtain administrative privileges. JFrog published a patch for it on August 28.

Earlier this month, security researchers told The Register that miscreants began battering internet-exposed systems vulnerable to CVE-2026-82329 just four days after JFrog disclosed the bug. In addition to creating new administrative credentials, watchTowr’s honeypot network caught miscreants “enumerating users, groups, credential sets and federated access topologies,” said Yordan Ganchev, principal threat intelligence specialist at watchTowr.

The one thing everyone agrees upon is that attackers didn’t start exploiting any of these CVEs until after JFrog issued fixes.

In a Thursday report, Wiz security researchers “confirmed in-the-wild exploitation of all three vulnerabilities across multiple environments,” and noted that “patching velocity has been slow.”

JFrog has not responded to any of The Register’s inquiries about attacks against any of the three CVEs.

'Patching velocity has been slow'

Six weeks after JFrog disclosed CVE-2026-42016, 59 percent of organizations remain vulnerable, and 62 percent remain vulnerable to CVE-2026-42018 after four weeks. Organizations have been quicker to remediate the critical bug, CVE-2026-82329, although 49 percent remain vulnerable two weeks after its publication, according to Wiz.

Beginning August 15 and running through September 8, Wiz spotted “multiple” attackers chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances to gain admin access. Many of these intruders then dropped a custom Rust backdoor to establish command-and-control (C2) capabilities. 

REG AD

While the post-exploitation activity varies, Wiz reports observing attackers doing all types of mischief with their administrative access to compromised Artifactory instances, including establishing persistent admin accounts, installing Groovy plugins to achieve remote code execution on the server, executing shell commands run through the plugin to perform reconnaissance and scan for sensitive files, deliver second-stage payloads, and upload web shells.

Then, between September 1 and 8, Wiz saw “several” attackers exploiting CVE-2026-82329. These intrusions were not a “unified attack chain by a single threat actor,” but spanned multiple illicit behaviors including exfiltration of configuration details, establishing persistent admin accounts, token minting for long-lived credentials, stealing keys, attaching their own SSH keys to created users in some cases, and enumerating users, repositories, and tokens.

If you haven't already, patch vulnerable instances

Wiz advises - and we strongly concur - upgrading to a fixed Artifactory version as soon as possible.

“Given that exploitation may be possible remotely without authentication under the default configuration, organizations should prioritize internet-accessible Artifactory instances and restrict network access to trusted users and systems where possible,” the researchers added. “Organizations should also review Artifactory authentication and administrative activity for unexpected privileged access.”

These latest exploits follow a rough few months for JFrog's package management system, which has been under fire from both human and AI attackers.

OpenAI and JFrog revealed that OpenAI’s models broke out of their cages to hack Hugging Face by exploiting an Artifactory zero-day in July, and at Black Hat, the model provider said agents used Artifactory to build message boards and help each other access the open internet.   ®

View the original on The Register

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.