Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploits Target JFrog Artifactory Vulnerabilities

Exploits Target JFrog Artifactory Vulnerabilities

Posted on September 11, 2026 By CWS

In a recent report by cloud security firm Wiz, it was revealed that attackers exploited two vulnerabilities in JFrog Artifactory, a popular repository used in software build pipelines, to gain administrator access to self-hosted servers and install backdoors. These exploits occurred between mid-August and early September.

Vulnerability Details and Exploitation

The flaws in question, identified as CVE-2026-42018 and CVE-2026-42016, were independently patched by JFrog before these attacks. However, only servers that had not implemented these updates were at risk. While neither vulnerability alone allowed admin access, their combination enabled attackers to compromise systems.

CVE-2026-42018 involved Artifactory issuing an anonymous user token without proper login, even when anonymous access was disabled. CVE-2026-42016 allowed this token to be upgraded to admin privileges, bypassing checks on token permissions. Attackers typically sent an unauthorized token request that was then exchanged for an admin-level token.

Attack Patterns and Consequences

Once inside, attackers swiftly created admin accounts and installed malicious plugins, giving them the ability to execute code on affected servers. Some even ran shell commands to investigate server files, while others installed a custom Rust backdoor for command-and-control operations. These activities were often completed in under five minutes from the initial attack.

The vulnerabilities affected a limited range of builds, and closing either flaw would prevent the exploit chain. JFrog’s patches were released in late April and August for different build branches, effectively mitigating these security issues.

Preventive Measures and Future Outlook

To protect against these vulnerabilities, JFrog recommends upgrading Artifactory to the latest fixed versions as outlined in their security advisories. For CVE-2026-82329, which allows unauthenticated admin access, a workaround involves modifying system configurations to restrict key registrations.

Despite these patches, attackers’ admin accounts persist unless manually removed, and compromised servers should be considered at risk. Security experts advise rotating platform keys and revoking recent access tokens to mitigate further damage.

In summary, vigilance and timely updates are crucial to preventing similar exploits. Organizations using JFrog Artifactory should regularly review their security practices to protect against evolving cyber threats.

The Hacker News Tags:administrator control, Artifactory, Attackers, cloud security, CVE, Cybersecurity, JFrog, security flaws, Software Security, Vulnerabilities

Post navigation

Previous Post: Windows Servers Face RDS Issues After September Updates
Next Post: Hackers Hide AI Threats in Plain English, Evade Security

Related Posts

MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide The Hacker News
Overcoming Risks from Chinese GenAI Tool Usage Overcoming Risks from Chinese GenAI Tool Usage The Hacker News
ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks The Hacker News
AI Tools Fuel Brazilian Phishing Scam While Efimer Trojan Steals Crypto from 5,000 Victims AI Tools Fuel Brazilian Phishing Scam While Efimer Trojan Steals Crypto from 5,000 Victims The Hacker News
PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse The Hacker News
Over 250 Domains Deploy Fingerprinting to Conceal macOS Threats Over 250 Domains Deploy Fingerprinting to Conceal macOS Threats The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark