ZoomEye finds 17,883 exposed JFrog Artifactory instances amid CVE-2026-82329
CISA added an authentication bypass in self-hosted JFrog Artifactory, CVE-2026-82329, to its Known Exploited Vulnerabilities catalog; rated 9.8, it grants administrator access without authentication. ZoomEye counted 17,883 assets by fingerprint and 40,523 by body content on September 19, with reporting describing a three-flaw chain and persistent admin accounts.
- CVE-2026-82329 in JFrog Artifactory is rated 9.8 and grants admin access unauthenticated
- ZoomEye: 17,883 assets by fingerprint and 40,523 by body content on September 19
- Attackers created admin accounts, installed plugins and exported tokens and cluster keys
- Recommended: patch Artifactory, restrict admin endpoints and rotate tokens and keys
Read next
Security