JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
JFrog Artifactory is in an active exploitation wave involving CVE-2026-42018 and CVE-2026-42016, where attackers used the flaws to move from low-privilege access to administrator control on self-hosted Artifactory systems between August 15 and September 8, 2026. The activity includes rapid token abuse and account creation across multiple environments, and Wiz says attackers also chained CVE-2026-82329 to take admin control and deploy backdoors. CISA has since added the Artifactory flaws to its KEV catalog after reports of active exploitation. Related reports also describe post-exploitation use of malicious Groovy plugins, Rust-based backdoors, and compromise of vulnerable instances.
Related Happenings
JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)
Vulnerability
H score56
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
How related:
As previously reported by The Hacker News, attackers have been observed chaining the two Artifactory bugs alongside CVE-2026-82329 (CVSS score: 9.8) to take administrator control of self-hosted servers and deploy backdoors between August 15 and September 8, 2026.
About this happening:
JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016 were tied to active exploitation against self-hosted servers, with attackers chaining them to bypass...
JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)
VulnerabilityHow related: As previously reported by The Hacker News, attackers have been observed chaining the two Artifactory bugs alongside CVE-2026-82329 (CVSS score: 9.8) to take administrator control of self-hosted servers and deploy backdoors between August 15 and September 8, 2026.
About this happening: JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016 were tied to active exploitation against self-hosted servers, with attackers chaining them to bypass...
JFrog Artifactory custom Rust backdoor deployment
Malware Activity
H score34
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
How related:
“Across multiple cases, we observed a custom Rust backdoor with C2 capabilities being dropped.”
About this happening:
A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after...
JFrog Artifactory custom Rust backdoor deployment
Malware ActivityHow related: “Across multiple cases, we observed a custom Rust backdoor with C2 capabilities being dropped.”
About this happening: A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
H score53
First: 05.09.2026 10:31
Last: 05.09.2026 10:31
Sources 1
About this happening:
PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation WaveAbout this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
Vulnerability
H score56
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under def...
JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
VulnerabilityAbout this happening: CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under def...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
H score55
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation WaveAbout this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
Timeline
-
11.09.2026 19:29 3 articles · 10d ago
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Initial DisclosureBetween August 15 and September 8, 2026, attackers used CVE-2026-42018 and CVE-2026-42016 to move from low-privilege access to administrator control on self-hosted Artifactory systems. Early activity already showed rapid token abuse and account creation across multiple environments.
Show sources
- Artifactory flaws chained in attacks deploying backdoor malware — www.bleepingcomputer.com — 11.09.2026 19:29
- Artifactory flaws chained in attacks deploying backdoor malware — www.bleepingcomputer.com — 11.09.2026 19:29
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV — thehackernews.com — 12.09.2026 18:54