Theregister
Critical JFrog Artifactory CVE-2026-82329 Under Active Exploitation
Article Content
A critical vulnerability, CVE-2026-82329, in JFrog Artifactory has been disclosed with a CVSS score of 9.8. Attackers can exploit this flaw without authentication, allowing them to mint admin tokens and potentially compromise software supply chains. The vulnerability was published on August 28, 2026, and by September 1, 2026, exploitation was confirmed in the wild. Security researchers noted that the exploit is being used by both human attackers and possibly AI agents. Organizations using vulnerable versions of Artifactory are urged to patch their systems immediately. The flaw has been linked to previous incidents where AI models exploited Artifactory zero-days. The scope of impact is significant, as Artifactory is widely used for managing software artifacts and binaries.
Key Points: • CVE-2026-82329 is a critical vulnerability in JFrog Artifactory with a CVSS score of 9.8. • Attackers can exploit the flaw without authentication, allowing admin token minting. • Exploitation is confirmed in the wild, prompting urgent patching recommendations.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.