September 13, 2026
- JFrog Artifactory is under active exploitation via a two-flaw chain plus a separate auth bypass. Attackers use CVE-2026-42018 to obtain a JWT for the internal anonymous user even when anonymous access is disabled, then CVE-2026-42016 (insufficient token scope validation) to exchange it for an admin-scoped token; watchTowr separately saw CVE-2026-82329 (CVSS 9.8 auth bypass) used to mint admin tokens earlier this month. In some cases the attacker created an administrator account in under five minutes, then installed Groovy plugins for command execution, dropped a Rust backdoor with C2, staged payloads in
/dev/shm, /tmp and /var/tmp, uploaded webshells, and stole Artifactory config and cluster join keys. Wiz puts 49–62% of reachable Artifactory instances as vulnerable to at least one of the three (BleepingComputer, Wiz). CISA listed them alongside exploited ConnectWise ScreenConnect and MikroTik RouterOS flaws (The Hacker News).
· Vulnerabilities & Exploitation
in Artifactory Chains Give Attackers Admin in Under Five Minutes
September 4, 2026
- CISA added seven actively exploited flaws to KEV, spanning an unusually broad stack: CVE-2026-83548 (SonicWall SMA 1000 pre-auth SSRF, CVSS 10.0), CVE-2026-82329 (JFrog Artifactory auth bypass), CVE-2026-9586 (Sangoma Switchvox pre-auth SQLi), CVE-2026-59822 (BerriAI LiteLLM improper authentication), CVE-2026-48710 (Starlette request smuggling) and CVE-2026-49869 (Kestra OSS command injection) (CISA). Observed post-exploitation is reverse shells and crypto miners (The Hacker News); the Artifactory bug is being used to forge admin tokens (BleepingComputer). LiteLLM sitting in KEV is the signal to watch — AI gateway middleware is now in the exploited-in-the-wild category.
· Exploitation & Vulnerabilities
in Malware That Gaslights the AI Analyst
September 2, 2026
- JFrog Artifactory CVE-2026-82329 (CVSS 9.8) is being exploited to mint admin tokens, days after disclosure, per watchTowr (The Hacker News, SecurityWeek). This is an artifact repository sitting inside build pipelines — admin there is supply-chain access (earlier coverage).
· Exploited in the Wild
- CVE-2026-82329 Artifactory lab — a reproducible Docker environment, URL-parameter validator PoC, and patch-diff analysis for the Artifactory auth bypass, useful for validating detection and confirming exposure (GitHub).
· New Tools & Releases
in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
September 1, 2026
- JFrog Artifactory auth bypass CVE-2026-82329 is being exploited, with attackers "minting themselves admin tokens," according to watchTowr. Artifactory sits directly on build and release pipelines, so admin-level access is artifact-poisoning reach, not just data access. Single-vendor telemetry so far — treat exposure checks as urgent regardless.
· Exploitation in the Wild
in Attackers Are Living in the Management Plane