Artifactory Exposure Measured Behind CVE-2026-82329
A critical authentication bypass, CVE-2026-82329, was found in self-hosted JFrog Artifactory with a CVSS score of 9.8, letting unauthenticated attackers gain admin rights. ZoomEye shows 17,874 Artifactory instances exposed online, 8,235 of them in the U.S.; exploitation was seen three days after disclosure on August 28, 2026.
- CVE-2026-82329 is an auth bypass in JFrog Access, CVSS 9.8
- Attack forges a join JWT and issues a platform admin token
- ZoomEye: 17,874 Artifactory instances exposed to the internet
- 8,235 instances (46%) are located in the United States
Read next
Security