chiprook
← Security
SecurityOctober 11, 2026, 10:40

Three JFrog Artifactory Flaws Added to CISA KEV Catalog

CISA added three JFrog Artifactory vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-82329 (CVSS 9.8, unauthenticated admin access) on September 2, 2026, and CVE-2026-42016 (CVSS 8.1, token scope bypass) and CVE-2026-42018 (CVSS 7.5, anonymous token leak) on September 11. The fix is Artifactory Self-Hosted 7.133.11 or later.

Three JFrog Artifactory Flaws Added to CISA KEV Catalog
#JFrog#Artifactory#CISA
Read next
Security

JFrog patches three Artifactory flaws exploited together in the wild

Security

JFrog Artifactory Under Active Attack: Three CVEs Chained

Security

CISA adds JFrog Artifactory auth bypass to exploited vulnerabilities list

Security

CISA adds critical Kestra CVE-2026-49869 to KEV catalog