More JFrog Artifactory bugs under attack, and all 3 have patches
If you're waiting for a sign to upgrade to a fixed version: this is it
JFrog Artifactory instances are facing multiple attacks due to three security vulnerabilities that have been exploited. These vulnerabilities include CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329. The first vulnerability, CVE-2026-42018, is a high-severity improper authentication flaw that can allow attackers to access sensitive resources.
It was patched by JFrog on August 12. However, 59 percent of organizations still remain vulnerable six weeks after the disclosure. The second vulnerability, CVE-2026-42016, is also a high-severity privilege escalation bug, allowing an attacker with low-privileged access to elevate privileges. It was fixed on July 27, but 59 percent of organizations remain vulnerable after four weeks.
The third vulnerability, CVE-2026-82329, is a critical authentication-bypass vulnerability that allows unauthenticated attackers to gain administrative privileges. JFrog patched this one on August 28. The researchers found that attackers began exploiting all three vulnerabilities after the vendor published the patches. They found attackers chaining the vulnerabilities to gain admin access and then install malicious plugins and backdoors.
These attackers were then able to perform various malicious activities such as establishing persistent admin accounts, installing Groovy plugins for remote code execution, executing shell commands, scanning for sensitive files, delivering second-stage payloads, and uploading web shells. Wiz security researchers advise organizations to patch vulnerable instances as soon as possible, especially those that are internet-accessible, and restrict network access to trusted users and systems.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- More JFrog Artifactory bugs under attack, and all 3 have patches theregister.com