Skip to content
JFrog Artifactory Vulnerabilities Enable Rapid Admin Access Exploitation

JFrog Artifactory Vulnerabilities Enable Rapid Admin Access Exploitation

First seen 29 Sep 2026, 00:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 00:10 UTC
  • •Three critical vulnerabilities in JFrog Artifactory allow rapid admin access.
  • •Attackers can exploit these flaws in under five minutes, posing a significant risk.
  • •Organizations must patch affected versions and investigate potential compromises.

Attackers are exploiting three vulnerabilities in self-hosted JFrog Artifactory to gain administrator access in under five minutes. The vulnerabilities, CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, allow for authentication bypass and privilege escalation. Attackers can chain these flaws to create persistent admin accounts, steal credentials, and execute arbitrary code. The flaws are rated high to critical severity, with CVE-2026-82329 being critical. Security firm Wiz.io reported that the attack method involves sending unauthenticated HTTP requests to exploit these vulnerabilities. Organizations with exposed Artifactory instances are urged to assume compromise and investigate for signs of exploitation. Patching the vulnerabilities is necessary to close the entry points but does not remove any existing intruders. The vulnerabilities were added to CISA's KEV catalog due to active exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-27
CVE-2026-42016 published
CVE-2026-42016 was published, allowing unauthorized actions via low-privileged tokens.
Infoq
2026-08-12
CVE-2026-42018 published
CVE-2026-42018 was published, allowing unauthenticated users to receive internal tokens.
Infoq
2026-08-28
CVE-2026-82329 published
CVE-2026-82329 was published, enabling unauthenticated attackers to gain admin control.
Infoq
2026-09-02
CVE-2026-82329 added to CISA KEV
CVE-2026-82329 was added to the CISA KEV catalog due to active exploitation.
News.Lavx.Hu
2026-09-11
CVE-2026-42016 and CVE-2026-42018 added to CISA KEV
CVE-2026-42016 and CVE-2026-42018 were added to the CISA KEV catalog due to active exploitation.
Infoq

More articles in this cluster (3)

Following this threat?

Track CVE-2026-42016 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed