Three JFrog Artifactory Flaws Actively Exploited to Gain Administrator Access

Security researchers have recorded attacks against self-hosted JFrog Artifactory servers in which attackers exploited three patched vulnerabilities to gain administrative privileges and establish persistence.

JFrog Artifactory flaws CVE-2026-42018, CVE-2026-42016 and CVE-2026-82329 are reportedly being actively exploited against self-hosted instances. In observed incidents, attackers gained administrative privileges and in some cases deployed plugins and a backdoor. JFrog has released fixes for all three vulnerabilities.

JFrog Artifactory flaws provide a path to administrator access

Researchers observed the first two flaws being chained during attacks between August 15 and September 8, 2026. CVE-2026-42018 may allow an unauthenticated caller to obtain an internal token for the anonymous user even when anonymous access is disabled. CVE-2026-42016 is an insufficient authorization flaw affecting user tokens that may lead to privilege escalation.

According to findings by Wiz, reported by multiple independent media outlets, the actors combined these two vulnerabilities to gain administrator access to Artifactory servers. In some cases, they then deployed Groovy plugins and a Rust-written backdoor with functionality for communicating with a command-and-control server.

The third flaw, critical CVE-2026-82329, is a potential authentication bypass leading to administrator access. JFrog disclosed it on August 28, 2026. According to available reports, attackers also exploited it independently, from September 1 to 8.

Risk to repositories and build processes

Artifactory is used to store and distribute software packages in development, build and deployment processes. Administrator access may therefore allow an attacker to modify configurations or artifacts, create persistent accounts or execute code through plugins.

The deployment of plugins and a backdoor means that updating alone may not be sufficient if a breach has already occurred. A fix removes the vulnerability, but it does not automatically remove administrator accounts, tokens, plugins or other persistence created by the attacker.

Operators should deploy fixes and inspect servers

Operators of their own instances should prioritize deploying the fixes released by JFrog for all three CVEs. At the same time, it makes sense to restrict network access to the Artifactory interface and conduct a forensic review if compromise is suspected.

The review should focus especially on administrator accounts, issued tokens, installed plugins and system logs. Traces of unusual activity between mid-August and early September, when the attacks were observed, are also relevant.

It has not been publicly confirmed how many organizations or servers were compromised. The attacks have also not been attributed to a specific group; Wiz said they were not part of a unified campaign by a single actor. The company’s estimate of the share of publicly accessible vulnerable instances is not an independently verified worldwide count.

Further developments may include the addition of individual CVEs to the CISA Known Exploited Vulnerabilities catalog, new indicators of compromise, more precise data on the scope of the attacks or additional mitigations from JFrog for already attacked servers.

Sources

  • JFrog Security Advisories – Primary source on the existence, severity, affected versions and availability of fixes for CVE-2026-42018, CVE-2026-42016 and CVE-2026-82329.
  • The Register – Corroborates Wiz’s observations of the exploitation of three flaws, the attack periods and post-exploitation activity including the Rust backdoor.
  • BleepingComputer – Corroborates the chaining mechanism for CVE-2026-42018 and CVE-2026-42016 and the reported deployment of malicious plugins and persistence.
  • SecurityWeek – Original supplied source for the claim that three flaws were exploited to bypass authentication, escalate privileges and deploy a backdoor.

Verified and updated: September 14, 2026 16:40

Sharing