JFrog Artifactory bugs under active exploitation as attackers chain flaws to seize admin control

Three vulnerabilities patched over past two months remain widely unaddressed, with Wiz and watchTowr reporting multiple intrusion campaigns

edit
By LineZotpaper
Published
Read Time2 min
Attackers are actively exploiting three vulnerabilities in JFrog Artifactory — including a critical authentication bypass — to gain administrative access, install backdoors, and exfiltrate credentials, with security firms warning that many organisations have been slow to apply patches.

Security researchers at Wiz and watchTowr have documented multiple exploitation campaigns targeting JFrog Artifactory instances, using a trio of vulnerabilities that were patched between July and August. The bugs — designated CVE-2026-42016 (high-severity privilege escalation, patched July 27), CVE-2026-42018 (high-severity improper authentication, patched August 12), and CVE-2026-82329 (critical authentication bypass, patched August 28) — are being used in combination to take over self-hosted Artifactory servers.

According to Wiz, exploitation of CVE-2026-42018 and CVE-2026-42016 began as early as August 15, with attackers chaining the flaws to create persistent admin accounts, install Groovy plugins for remote code execution, and deploy a custom Rust backdoor for command-and-control. Between September 1 and 8, a separate wave exploited CVE-2026-82329, which allows unauthenticated attackers with network access to obtain admin privileges. watchTowr observed adversaries enumerating users, groups, and federated access topologies.

Patching progress has been uneven. Wiz reports that six weeks after the disclosure of CVE-2026-42016, 59% of organisations remain vulnerable. For CVE-2026-42018, 62% were still unpatched after four weeks. Even for the critical CVE-2026-82329, 49% of environments remained exposed two weeks after the patch was issued.

Post-exploitation activity has included token minting for long-lived credentials, SSH key attachment, and theft of configuration details. JFrog has not responded to inquiries about the attacks. The vendor’s patches address all three vulnerabilities; administrators are urged to upgrade internet-accessible Artifactory instances as a priority.

§

Analysis

Why This Matters

  • Artifactory is a core component in many software supply chains; full admin access can lead to backdoored binaries or credentials for other systems.
  • Slow patch adoption — nearly half of environments still vulnerable two weeks after a critical fix — suggests organisations are not prioritising remediation despite known active exploitation.
  • The use of custom backdoors and persistence mechanisms indicates that attackers intend to maintain long-term access.

Background

JFrog Artifactory is a widely used binary repository manager that stores, manages, and distributes software artifacts. It is commonly deployed in CI/CD pipelines, making it a high-value target. The three vulnerabilities discovered this year affect self-hosted instances; cloud-hosted versions may differ. All three bugs were patched within weeks of disclosure, but in-the-wild exploitation began only after patches were available, a pattern typical of attackers reverse-engineering fixes.

Key Perspectives

Security researchers (Wiz, watchTowr): They have documented active, multi-actor exploitation and stress that internet-accessible instances are at greatest risk. They recommend immediate patching and network restriction. JFrog: The vendor has released patches for all three CVEs but has not publicly commented on the attacks or provided additional guidance beyond advisory notices. Organisations using self-hosted Artifactory: Many appear to be slow to patch, potentially due to operational complexity or lack of awareness. The window of vulnerability remains wide.

What to Watch

  • Whether patching rates for CVE-2026-82329 accelerate now that active exploitation is widely reported.
  • Indicators of supply chain compromise: any reports of tampered artifacts or downstream breaches traced to compromised Artifactory instances.
  • Possible disclosure of additional CVEs or attack chains as researchers continue to monitor honeypots.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.