Urgent.News

What's breaking now, across thousands of outlets.

Science

More JFrog Artifactory bugs under attack, and all 3 have patches

If you're waiting for a sign to upgrade to a fixed version: this is it

More JFrog Artifactory bugs under attack, and all 3 have patches

JFrog Artifactory, a widely used package management system, continues to face multiple attacks due to recently disclosed vulnerabilities. Three separate bugs, each with a varying severity, have been exploited by attackers to gain administrative control over vulnerable instances. The first, CVE-2026-42018, is a high-severity improper authentication flaw that allows an attacker to gain access to sensitive resources if they can obtain an internal anonymous-user token.

This vulnerability was patched on August 12, but 59% of organizations still remain vulnerable six weeks after JFrog disclosed the fix. The second vulnerability, CVE-2026-42016, is a privilege escalation bug that allows an attacker with low-privileged access to elevate their privileges and perform unauthorized actions. JFrog fixed this issue on July 27, but 62% of organizations remain vulnerable four weeks later.

The third and critical vulnerability, CVE-2026-82329, is an authentication bypass flaw that enables unauthenticated attackers to gain administrative privileges. JFrog issued a patch for this vulnerability on August 28, but 49% of organizations still remain vulnerable two weeks after its publication. Security researchers have observed attackers chaining these vulnerabilities together to gain access to self-hosted Artifactory instances and install malicious plugins, backdoors, and establish persistent admin access.

Wiz security researchers recommend that organizations prioritize patching their vulnerable Artifactory instances as soon as possible, as exploitation may be possible remotely without authentication under the default configuration.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Science

More from Friday 11 September →