{
  "id": 6815814,
  "title": "More JFrog Artifactory bugs under attack, and all 3 have patches",
  "url": "https://urgent.news/2026/09/11/more-jfrog-artifactory-bugs-under-attack-and-all-3-have-patches",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-11T17:43:30.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/11/more-jfrog-artifactory-bugs-under-attack-and-all-3-have-patches/5295943"
  },
  "original_language": "en",
  "account": "JFrog Artifactory, a widely used package management system, continues to face multiple attacks due to recently disclosed vulnerabilities. Three separate bugs, each with a varying severity, have been exploited by attackers to gain administrative control over vulnerable instances. The first, CVE-2026-42018, is a high-severity improper authentication flaw that allows an attacker to gain access to sensitive resources if they can obtain an internal anonymous-user token. This vulnerability was patched on August 12, but 59% of organizations still remain vulnerable six weeks after JFrog disclosed the fix. The second vulnerability, CVE-2026-42016, is a privilege escalation bug that allows an attacker with low-privileged access to elevate their privileges and perform unauthorized actions. JFrog fixed this issue on July 27, but 62% of organizations remain vulnerable four weeks later. The third and critical vulnerability, CVE-2026-82329, is an authentication bypass flaw that enables unauthenticated attackers to gain administrative privileges. JFrog issued a patch for this vulnerability on August 28, but 49% of organizations still remain vulnerable two weeks after its publication. Security researchers have observed attackers chaining these vulnerabilities together to gain access to self-hosted Artifactory instances and install malicious plugins, backdoors, and establish persistent admin access. Wiz security researchers recommend that organizations prioritize patching their vulnerable Artifactory instances as soon as possible, as exploitation may be possible remotely without authentication under the default configuration.",
  "summary": "If you're waiting for a sign to upgrade to a fixed version: this is it",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "More JFrog Artifactory bugs under attack, and all 3 have patches",
        "url": "https://urgent.news/2026/09/11/more-jfrog-artifactory-bugs-under-attack-and-all-3-have-patches-6818227",
        "published": "2026-09-11T17:43:30.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}