chiprook
← Security
SecurityOctober 4, 2026, 08:52

JFrog Artifactory Under Active Attack: Three CVEs Chained

A Wiz report describes four weeks of active exploitation of self-hosted JFrog Artifactory, where attackers chain CVE-2026-42018 and CVE-2026-42016 to turn a single unauthenticated request into an admin-scoped token in under five minutes. A separate flaw, CVE-2026-82329 (CVSS 9.8), grants an admin token under default configuration. All three CVEs are on CISA's KEV catalog, with a September 25 remediation deadline for two.

JFrog Artifactory Under Active Attack: Three CVEs Chained
#JFrog#Artifactory#CISA
Read next
Security

Default Join Key Let Attackers Mint Admin Tokens on JFrog Artifactory

Security

JFrog patches three Artifactory flaws exploited together in the wild

Security

ZoomEye finds 17,883 exposed JFrog Artifactory instances amid CVE-2026-82329

Security

CISA adds JFrog Artifactory auth bypass to exploited vulnerabilities list