JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016 were tied to active exploitation against self-hosted servers, with attackers chaining them to bypass authentication, steal JWTs, and reach admin-level access. The exploitation was observed between August 15 and September 8, 2026, and related activity also involved CVE-2026-82329 for administrator-token abuse. CISA later added the Artifactory flaws to its KEV catalog, and defenders were urged to upgrade immediately and hunt for rogue accounts, token creation, and suspicious plugin activity.
Related Happenings
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation Wave
H score56
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
How related:
Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token.
About this happening:
JFrog Artifactory is in an active exploitation wave involving CVE-2026-42018 and CVE-2026-42016, where attackers used the flaws to move from low-privilege access t...
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation WaveHow related: Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token.
About this happening: JFrog Artifactory is in an active exploitation wave involving CVE-2026-42018 and CVE-2026-42016, where attackers used the flaws to move from low-privilege access t...
JFrog Artifactory custom Rust backdoor deployment
Malware Activity
H score34
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
How related:
“Across multiple cases, we observed a custom Rust backdoor with C2 capabilities being dropped.”
About this happening:
A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after...
JFrog Artifactory custom Rust backdoor deployment
Malware ActivityHow related: “Across multiple cases, we observed a custom Rust backdoor with C2 capabilities being dropped.”
About this happening: A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after...
JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
Vulnerability
H score56
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under def...
JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
VulnerabilityAbout this happening: CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under def...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
H score55
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation WaveAbout this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
Timeline
-
11.09.2026 19:29 3 articles · 10d ago
Wiz confirms active JFrog Artifactory exploitation and Rust backdoor deployment
Initial DisclosureWiz confirmed multiple threat actors chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory servers to obtain internal anonymous-user JWTs, exchange them for admin-scoped tokens, create administrator accounts in under five minutes, and deploy a Rust-based backdoor with C2. The analysis also says watchTowr observed CVE-2026-82329 being exploited earlier this month to mint administrator tokens, and JFrog administrators should upgrade immediately and look for unexpected token creation, rogue administrator accounts, suspicious Groovy plugin activity, and enumeration requests.
Show sources
- Artifactory flaws chained in attacks deploying backdoor malware — www.bleepingcomputer.com — 11.09.2026 19:29
- Artifactory flaws chained in attacks deploying backdoor malware — www.bleepingcomputer.com — 11.09.2026 19:29
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV — thehackernews.com — 12.09.2026 18:54