Three JFrog Artifactory Flaws Added to CISA KEV Catalog
CISA added three JFrog Artifactory vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-82329 (CVSS 9.8, unauthenticated admin access) on September 2, 2026, and CVE-2026-42016 (CVSS 8.1, token scope bypass) and CVE-2026-42018 (CVSS 7.5, anonymous token leak) on September 11. The fix is Artifactory Self-Hosted 7.133.11 or later.
- CVE-2026-82329: CVSS 9.8, unauthenticated attacker gains admin privileges
- CVE-2026-42016: CVSS 8.1, token signature and issuer checked but not scope
- CVE-2026-42018: CVSS 7.5, internal anonymous token leaked when anonymous access is off
- Fix: Artifactory Self-Hosted 7.133.11 or later
Read next
Security