Vulnerabilities

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.

Exploit

A critical vulnerability in JFrog Artifactory is reportedly being exploited in the wild just days after its public disclosure. 

JFrog Artifactory is a widely used solution for managing the full lifecycle of software artifacts, binaries, AI models, containers, and packages.

Artifactory updates released on August 28 patch CVE-2026-82329, a critical authentication bypass vulnerability that can lead to admin access. 

“JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges,” JFrog noted in its advisory.

The company said the patches have already been rolled out to cloud instances, but customers using Artifactory in a self-hosted environment have been advised to update to one of the patched versions, including 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20.

Exposure management firm WatchTowr reported on Tuesday that it has already seen in-the-wild exploitation of CVE-2026-82329, “with attackers minting themselves admin tokens”.

Advertisement. Scroll to continue reading.

“Data from watchTowr’s global Attacker Eye honeypot network shows attackers minting administrator tokens and enumerating users, groups, credential sets and federated access topologies,” said Yordan Ganchev, principal threat intelligence specialist at WatchTowr.

“When attackers gain admin level access of a central software supply chain system, they can do what every engineering team does best – build, ship and distribute software fast. From there, they could tamper with build pipelines, move laterally into production systems and potentially push malicious changes downstream to customers,” Ganchev added.

There do not appear to be any other reports of active exploitation at the time of writing.

JFrog has yet to confirm active exploitation, but the company’s CTO, Yoav Landman, noted in a post on X that the vulnerability allows “improper authentication rather than RCE”, and “it does not affect the JFrog SaaS platform, only self-hosted deployments”.

CVE-2026-82329 may be the first Artifactory vulnerability exploited in malicious attacks, but it’s not the first to be exploited. 

A zero-day flaw in Artifactory was recently exploited by OpenAI models when they escaped a testing environment and hacked Hugging Face. 

OpenAI revealed recently that one of its models exploited the vulnerability CVE-2026-66384 while attempting to conduct a “container-image supply-chain attack by poisoning Artifactory’s container image cache”.

There do not appear to be any other reports describing the exploitation of CVE-2026-66384, but CISA has added it to its KEV catalog. The cybersecurity agency has yet to add the more recent CVE-2026-82329 to its KEV list.

Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild

Related: PaperCut Exploitation Escalates to Active Intrusions

Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Related Content

Vulnerabilities

The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.

ICS/OT

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Vulnerabilities

The security defect allows remote attackers to bypass authentication through argument bearer manipulation.

Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

Vulnerabilities

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.

Artificial Intelligence

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.

Vulnerabilities

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

Vulnerabilities

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version