Vulnerabilities

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator.

Vulnerability

Threat actors have been exploiting three high-severity vulnerabilities in JFrog Artifactory to compromise deployments and install backdoors, cybersecurity firm Wiz reports.

Many organizations use Artifactory to manage software artifacts, binaries, AI models, containers, and packages.

The three flaws, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, can allow attackers to bypass authentication and gain administrative privileges on vulnerable Artifactory instances.

An improper authentication bug patched on August 12, CVE-2026-42018 can be exploited to obtain an anonymous-user token that provides access to sensitive artifacts and repository data. 

Patched on July 27, CVE-2026-42016 is an insufficient token validation issue that can be exploited for privilege escalation.

CVE-2026-82329 is an authentication bypass patched on August 28 that could be exploited remotely without authentication to gain administrative privileges. In-the-wild exploitation was reported a few days later.

Advertisement. Scroll to continue reading.

According to Wiz, CVE-2026-42018 and CVE-2026-42016 have been chained together since mid-August to obtain the anonymous-user token and then use it to elevate privileges to administrator.

“Between August 15 and September 8, 2026, we observed multiple actors chain CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances,” Wiz says.

The hackers were seen deploying persistent admin accounts, installing malicious plugins to gain arbitrary code execution, running shell commands through the plugin endpoint, dropping second-stage payloads, and occasionally updating the scripts for continuous access.

Multiple threat actors also started exploiting CVE-2026-82329 in the first week of September, for configuration exfiltration, persistent admin access, token minting, cluster key exfiltration, and asset enumeration.

In some instances, the attackers were seen attaching their own SSH keys to the user accounts they created.

On Friday, CISA added CVE-2026-42018 and CVE-2026-42016 to its KEV catalog, one week after it added CVE-2026-82329 to the list. In line with BOD 26-04, federal agencies were given two weeks to patch their vulnerable instances.

All organizations are advised to update their self-managed Artifactory deployments to versions 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, or 7.111.21 as soon as possible.

Related: GitLab Vulnerability Exploited One Day After Disclosure

Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Related: PaperCut Flaws Exploited in AI-Powered Attacks

Related: Critical NetScaler Vulnerability Exploited in Attacks

Related Content

Vulnerabilities

The flaw allows attackers to send files and execute them without authorization through an active remote session.

Vulnerabilities

Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

Vulnerabilities

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Vulnerabilities

Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.

Vulnerabilities

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version