JFrog Artifactory: CISA Adds Two Vulnerabilities to Known Exploited List

CISA added CVE-2026-42016 and CVE-2026-42018 in self-hosted JFrog Artifactory to the KEV Catalog. Wiz observed them being chained, which may lead to administrative access.

JFrog Artifactory contains vulnerabilities CVE-2026-42016 and CVE-2026-42018, which CISA added to the Known Exploited Vulnerabilities (KEV) Catalog on September 11, 2026. The agency thereby confirmed their known exploitation in the wild. The vulnerabilities affect self-hosted deployments of the JFrog Artifactory artifact repository.

According to researchers at Wiz, attackers chained both vulnerabilities against self-hosted instances between August 15 and September 8. The combination of flaws was reportedly able to let them move from an unauthenticated request to a token with an administrative permissions scope.

JFrog Artifactory: Two Vulnerabilities in One Chain

When anonymous access is disabled, CVE-2026-42018 can issue an internal anonymous-user token to an unauthenticated caller. The second vulnerability, CVE-2026-42016, is an authorization flaw in Artifactory versions older than 7.133.11. Insufficient token-scope validation may lead to privilege escalation.

According to Wiz, chaining these two vulnerabilities is significant: a token obtained through the first vulnerability can then be abused through the second to obtain an administrative scope. For both identifiers, CISA lists inclusion in KEV, the catalog of vulnerabilities with known exploitation.

JFrog Artifactory Fixes Are Available

JFrog has released security fixes. For CVE-2026-42016, the vendor lists version 7.133.11 as the fixed version for self-hosted deployments. For CVE-2026-42018, the vendor lists fixed releases for the affected product branches.

Administrators should prioritize updating affected self-hosted instances according to JFrog’s security guidance. Since CISA has recorded known exploitation, a forensic review of systems for signs of unauthorized access is also appropriate.

Successful acquisition of administrative privileges could put artifacts stored in the repository, credentials, and integrations used in the software supply chain at risk. For unpatched self-hosted servers, the combination of vulnerabilities may provide a path from an unauthenticated request to administrative access.

The Campaign’s Scope Is Not Yet Known

The full number of compromised organizations is not publicly known, nor has the campaign’s attribution to a specific threat group been independently confirmed. In its research, Wiz also reported the deployment of Rust backdoors and the creation of persistent administrative accounts; however, these findings have not been publicly confirmed by JFrog or CISA.

Further information may come from potential indicators of compromise from the vendor, CISA, or other security teams. It will also be important to monitor whether JFrog updates the list of affected versions or recommendations for cloud deployments.

Sources

Verified and updated: September 12, 2026 06:24

Sharing