JFrog patches three Artifactory flaws exploited together in the wild
JFrog released fixes for three self-hosted Artifactory vulnerabilities: authentication bypass CVE-2026-82329 (CVSS 9.8), CVE-2026-42018 (7.5) and CVE-2026-42016 (8.1). CISA added them to its Known Exploited Vulnerabilities catalog on September 12, 2026, with a federal remediation deadline of September 25.
- CVE-2026-82329 rated 9.8 lets attackers forge a platform admin token via an empty join key
- Fixed versions: 7.161.20 for one branch and 7.133.11 for the other two flaws
- CISA added the flaws to KEV on September 12 with a September 25 deadline
- Attackers create admin accounts, install malicious plugins and steal CI/CD tokens
Read next
Security