Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.

Exploit

A critical vulnerability in JFrog Artifactory is reportedly being exploited in the wild just days after its public disclosure. 

JFrog Artifactory is a widely used solution for managing the full lifecycle of software artifacts, binaries, AI models, containers, and packages.

Artifactory updates released on August 28 patch CVE-2026-82329, a critical authentication bypass vulnerability that can lead to admin access. 

“JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges,” JFrog noted in its advisory.

The company said the patches have already been rolled out to cloud instances, but customers using Artifactory in a self-hosted environment have been advised to update to one of the patched versions, including 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20.

Exposure management firm WatchTowr reported on Tuesday that it has already seen in-the-wild exploitation of CVE-2026-82329, “with attackers minting themselves admin tokens”.

Advertisement. Scroll to continue reading.

“Data from watchTowr’s global Attacker Eye honeypot network shows attackers minting administrator tokens and enumerating users, groups, credential sets and federated access topologies,” said Yordan Ganchev, principal threat intelligence specialist at WatchTowr.

“When attackers gain admin level access of a central software supply chain system, they can do what every engineering team does best – build, ship and distribute software fast. From there, they could tamper with build pipelines, move laterally into production systems and potentially push malicious changes downstream to customers,” Ganchev added.

There do not appear to be any other reports of active exploitation at the time of writing.

JFrog has yet to confirm active exploitation, but the company’s CTO, Yoav Landman, noted in a post on X that the vulnerability allows “improper authentication rather than RCE”, and “it does not affect the JFrog SaaS platform, only self-hosted deployments”.

CVE-2026-82329 may be the first Artifactory vulnerability exploited in malicious attacks, but it’s not the first to be exploited. 

A zero-day flaw in Artifactory was recently exploited by OpenAI models when they escaped a testing environment and hacked Hugging Face. 

OpenAI revealed recently that one of its models exploited the vulnerability CVE-2026-66384 while attempting to conduct a “container-image supply-chain attack by poisoning Artifactory’s container image cache”.

There do not appear to be any other reports describing the exploitation of CVE-2026-66384, but CISA has added it to its KEV catalog. The cybersecurity agency has yet to add the more recent CVE-2026-82329 to its KEV list.

Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild

Related: PaperCut Exploitation Escalates to Active Intrusions

Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Sectigo has named Ian Hassard as Chief Product Officer.

Australian Securities Exchange has appointed Hanlie Botha as Deputy Chief Information Security Officer.

Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.