September 13, 2026
- JFrog Artifactory is under active exploitation via a two-flaw chain plus a separate auth bypass. Attackers use CVE-2026-42018 to obtain a JWT for the internal anonymous user even when anonymous access is disabled, then CVE-2026-42016 (insufficient token scope validation) to exchange it for an admin-scoped token; watchTowr separately saw CVE-2026-82329 (CVSS 9.8 auth bypass) used to mint admin tokens earlier this month. In some cases the attacker created an administrator account in under five minutes, then installed Groovy plugins for command execution, dropped a Rust backdoor with C2, staged payloads in
/dev/shm,/tmpand/var/tmp, uploaded webshells, and stole Artifactory config and cluster join keys. Wiz puts 49–62% of reachable Artifactory instances as vulnerable to at least one of the three (BleepingComputer, Wiz). CISA listed them alongside exploited ConnectWise ScreenConnect and MikroTik RouterOS flaws (The Hacker News). · Vulnerabilities & Exploitation
in Artifactory Chains Give Attackers Admin in Under Five Minutes