{
  "id": 7277729,
  "title": "More JFrog Artifactory Bugs Are Under Attack, and All Three Have Patches",
  "url": "https://urgent.news/2026/09/14/more-jfrog-artifactory-bugs-are-under-attack-and-all-three-have",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-14T08:30:52.000Z",
  "source": {
    "name": "DevOps.com",
    "slug": "devops-com",
    "url": "https://devops.com/more-jfrog-artifactory-bugs-are-under-attack-and-all-three-have-patches/"
  },
  "original_language": "en",
  "account": "Three critical vulnerabilities have been found in JFrog Artifactory, a repository manager for binaries, containers, and packages used in build pipelines. These vulnerabilities allow attackers to gain administrative control over the Artifactory instance, putting downstream products at risk. While patches are available for all three bugs, they have been slow to be applied. The most serious flaw, CVE-2026-82329, lets unauthenticated attackers gain administrative access. The other two flaws, CVE-2026-42018 and CVE-2026-42016, enable attackers to authenticate as if they belonged in the repository and escalate their privileges. Researchers found that attackers are combining these vulnerabilities to achieve full control. The exploitation of these patched bugs continues, with 49% of instances still vulnerable to CVE-2026-82329 two weeks after the fix. Experts suggest treating repository managers like internet-facing systems, patching them with the same urgency.",
  "summary": "Attackers are actively exploiting three JFrog Artifactory flaws, exposing how slow patching can turn artifact repositories into software supply chain attack paths.",
  "key_points": [
    "Three critical vulnerabilities found in JFrog Artifactory",
    "Unauthenticated attackers gain administrative access via CVE-2026-82329",
    "49% of instances still vulnerable to patched bugs two weeks later"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}