threat_intelligence345 wordsRead on Arc Codex

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

Threat actors have been exploiting three high-severity vulnerabilities in JFrog Artifactory to compromise deployments and install backdoors, cybersecurity firm Wiz reports. Many organizations use Artifactory to manage software artifacts, binaries, AI models, containers, and packages. The three flaws, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, can allow attackers to bypass authentication and gain administrative privileges on vulnerable Artifactory instances. An improper authentication bug patched on August 12, CVE-2026-42018 can be exploited to obtain an anonymous-user token that provides access to sensitive artifacts and repository data. Patched on July 27, CVE-2026-42016 is an insufficient token validation issue that can be exploited for privilege escalation. CVE-2026-82329 is an authentication bypass patched on August 28 that could be exploited remotely without authentication to gain administrative privileges. In-the-wild exploitation was reported a few days later. According to Wiz, CVE-2026-42018 and CVE-2026-42016 have been chained together since mid-August to obtain the anonymous-user token and then use it to elevate privileges to administrator. “Between August 15 and September 8, 2026, we observed multiple actors chain CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances,” Wiz says. The hackers were seen deploying persistent admin accounts, installing malicious plugins to gain arbitrary code execution, running shell commands through the plugin endpoint, dropping second-stage payloads, and occasionally updating the scripts for continuous access. Multiple threat actors also started exploiting CVE-2026-82329 in the first week of September, for configuration exfiltration, persistent admin access, token minting, cluster key exfiltration, and asset enumeration. In some instances, the attackers were seen attaching their own SSH keys to the user accounts they created. On Friday, CISA added CVE-2026-42018 and CVE-2026-42016 to its KEV catalog, one week after it added CVE-2026-82329 to the list. In line with BOD 26-04, federal agencies were given two weeks to patch their vulnerable instances. All organizations are advised to update their self-managed Artifactory deployments to versions 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, or 7.111.21 as soon as possible. Related: GitLab Vulnerability Exploited One Day After Disclosure Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Related: PaperCut Flaws Exploited in AI-Powered Attacks Related: Critical NetScaler Vulnerability Exploited in Attacks

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.