Artifactory Is Under Active Attack: 3 Checks in 30 Minutes
A research report published Thursday describes four weeks of active exploitation of JFrog Artifactory, the artifact registry that sits in front of most Java and DevOps build pipelines. Attackers chain two patched CVEs to turn a single unauthenticated request into an admin-scoped token, and the tell is uncomfortable: every request they make afterward shows up in your logs as token:anonymous , an…
Three security vulnerabilities were actively exploited in JFrog Artifactory artifact registries between August 15 and September 8. The exploitation chain involves two patched CVEs that enable attackers to bypass authentication and gain unauthorized admin privileges. This covert technique results in log entries appearing as token:anonymous, which blend into background noise and remain undetected.
The Common Vulnerabilities and Exposures (CVE) identifiers for these flaws are CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, with the latter being a default configuration bypass vulnerability. These vulnerabilities affect Artifactory versions from 7.133.11 through 7.161.20, with distinct impact levels ranging from high to critical.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.