JFrog Artifactory Under Active Attack: Three CVEs Chained
A Wiz report describes four weeks of active exploitation of self-hosted JFrog Artifactory, where attackers chain CVE-2026-42018 and CVE-2026-42016 to turn a single unauthenticated request into an admin-scoped token in under five minutes. A separate flaw, CVE-2026-82329 (CVSS 9.8), grants an admin token under default configuration. All three CVEs are on CISA's KEV catalog, with a September 25 remediation deadline for two.
- CVE-2026-42018: trailing-slash request returns an anonymous-user JWT
- CVE-2026-42016: token exchanged for admin scope due to missing scope validation
- CVE-2026-82329 (CVSS 9.8): admin token under default configuration
- Exploitation observed August 15 to September 8; all three CVEs on CISA KEV
Read next
Security