JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administrative access. The abuse began days after public disclosure and is focused on internet-exposed instances. Attackers are already using the flaw to mint admin tokens and enumerate users, groups, credential sets and federated access topologies. The rapid post-patch weaponization raises the risk of downstream tampering in software supply chain environments.
Related Happenings
JFrog Artifactory custom Rust backdoor deployment
Malware Activity
H score34
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
About this happening:
A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after...
JFrog Artifactory custom Rust backdoor deployment
Malware ActivityAbout this happening: A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after...
JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)
Vulnerability
H score56
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
About this happening:
JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016 were tied to active exploitation against self-hosted servers, with attackers chaining them to bypass...
JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016 were tied to active exploitation against self-hosted servers, with attackers chaining them to bypass...
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation Wave
H score56
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
About this happening:
JFrog Artifactory is in an active exploitation wave involving CVE-2026-42018 and CVE-2026-42016, where attackers used the flaws to move from low-privilege access t...
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation WaveAbout this happening: JFrog Artifactory is in an active exploitation wave involving CVE-2026-42018 and CVE-2026-42016, where attackers used the flaws to move from low-privilege access t...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
H score53
First: 05.09.2026 10:31
Last: 05.09.2026 10:31
Sources 1
About this happening:
PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation WaveAbout this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
CISA KEV multi-vulnerability exploitation wave
Exploitation Wave
H score59
First: 03.09.2026 08:19
Last: 03.09.2026 08:19
Sources 1
About this happening:
CISA's KEV list gained seven exploited flaws, signaling active abuse across SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Starlette, Kestra O...
CISA KEV multi-vulnerability exploitation wave
Exploitation WaveAbout this happening: CISA's KEV list gained seven exploited flaws, signaling active abuse across SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Starlette, Kestra O...
Timeline
-
01.09.2026 20:53 1 articles · 14d ago
JFrog releases Artifactory 7.161.20 to fix CVE-2026-82329
Mitigation Patch UpdateJFrog released Artifactory 7.161.20 on August 28, 2026 to patch CVE-2026-82329, an authentication bypass in JFrog Artifactory that could let an unauthenticated attacker with network access obtain administrative privileges under default configuration.
Show sources
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — thehackernews.com — 01.09.2026 20:53
-
01.09.2026 20:53 4 articles · 14d ago
Threat actors weaponize CVE-2026-82329 to mint admin tokens in JFrog Artifactory
Exploitation ObservedAs of September 1, 2026, threat actors had begun weaponizing CVE-2026-82329 against JFrog Artifactory, using the authentication bypass to generate admin tokens and enumerate users, groups, credential sets and federated access topologies.
Show sources
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — thehackernews.com — 01.09.2026 20:53
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — thehackernews.com — 01.09.2026 20:53
- Hackers exploit critical JFrog Artifactory flaw to forge admin tokens — www.bleepingcomputer.com — 02.09.2026 18:47
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors — thehackernews.com — 11.09.2026 10:31