Recent reports from cybersecurity firm Wiz reveal that threat actors are actively exploiting critical vulnerabilities in JFrog Artifactory. These flaws are allowing attackers to compromise systems and deploy backdoors, posing significant risks to many organizations.
Exploitation of Artifactory Flaws
JFrog Artifactory is widely used to manage software artifacts, binaries, AI models, containers, and packages. However, three vulnerabilities, identified as CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, are being exploited to bypass authentication and obtain administrative privileges on affected instances.
One of the vulnerabilities, CVE-2026-42018, was addressed with a patch on August 12. This flaw allows attackers to gain access to sensitive artifacts by obtaining an anonymous-user token. Another flaw, CVE-2026-42016, patched on July 27, involves insufficient token validation, which attackers can leverage for privilege escalation.
Security Breaches and Exploitation Tactics
On August 28, CVE-2026-82329, an authentication bypass, was patched. This vulnerability enables remote attackers to gain administrative privileges without authentication. Shortly after the patch, instances of in-the-wild exploitation were reported.
Wiz observed that from mid-August, attackers have been chaining CVE-2026-42018 and CVE-2026-42016 to escalate privileges to administrator level. Between August 15 and September 8, multiple threat actors targeted self-hosted Artifactory instances, creating persistent admin accounts and deploying malicious plugins for arbitrary code execution.
Mitigating the Risks
Beginning in September, CVE-2026-82329 was also exploited by several actors for configuration exfiltration and minting tokens, among other malicious activities. In some cases, attackers attached their own SSH keys to newly created user accounts, further compromising security.
In response, CISA added CVE-2026-42018 and CVE-2026-42016 to its Known Exploited Vulnerabilities (KEV) catalog, following the earlier addition of CVE-2026-82329. Federal agencies are mandated to patch these vulnerabilities in line with BOD 26-04 within two weeks.
Conclusion and Recommendations
Organizations using Artifactory are strongly advised to update to the latest versions: 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, or 7.111.21, to mitigate these risks. Staying ahead of potential threats by applying timely security patches is crucial to maintain secure operations.
For further insight into recent cybersecurity threats, related vulnerabilities in GitLab, Fortinet, and NetScaler have also been reported, highlighting the importance of continuous vigilance in cybersecurity practices.
