Wiz Reports Active Exploitation of Vulnerabilities in Self-Hosted JFrog Artifactory
Wiz researchers observed attacks chaining two vulnerabilities in self-hosted JFrog Artifactory to gain administrative access.

Exploitation of JFrog Artifactory is no longer merely a theoretical scenario. On September 10, Wiz announced observed attacks against self-hosted instances of the product in which attackers chained vulnerabilities CVE-2026-42018 and CVE-2026-42016. The combination may allow an unauthenticated attacker to gain administrative access to a vulnerable server.
According to Wiz, such attacks were recorded between August 15 and September 8, 2026. BleepingComputer also reported the researchers’ findings. However, the number or identities of compromised organizations have not been publicly confirmed, and the individual attacks have not been reliably attributed to a specific group.
How the JFrog Artifactory Exploitation Works
The first flaw in the chain, CVE-2026-42018, may provide an unauthenticated caller with an internal token belonging to an anonymous user, even when anonymous access is disabled. JFrog classifies it as High.
The second flaw, CVE-2026-42016, allows a low-privilege token to be elevated to a token with administrative scope. According to Wiz, chaining both flaws therefore leads from unauthenticated access to Artifactory administrator privileges.
After gaining administrative privileges, researchers say the attackers created new administrative accounts, deployed malicious Groovy plugins and, in some cases, a Rust backdoor with capabilities for communicating with command-and-control infrastructure. Such access may provide attackers with persistence on the server, access to configuration data and the ability to interfere with the internal artifact repository.
Self-Hosted Deployments Are Affected
The notice concerns self-hosted versions of JFrog Artifactory in the affected branches, not automatically every deployment of the product. JFrog has published fixes for CVE-2026-42018. Operators should verify the specific version in use and the scope of impact according to the vendor’s security recommendations.
Artifactory serves as a repository for software packages and artifacts used when developing and deploying applications. Administrative access to such infrastructure therefore gives an attacker an opportunity to affect the internal environment where an organization manages its builds and dependencies.
What Administrators Should Check
Because Wiz describes observed attacks, vulnerable self-hosted instances should be addressed as a priority. In addition to applying available fixes, administrators should specifically review administrative accounts, tokens and extensions installed in Artifactory.
- new or unexpected administrative accounts,
- long-lived tokens and their permissions,
- unknown Groovy plugins,
- logs of administrative operations performed using an anonymous user token,
- unusual binary files in temporary directories,
- suspicious outbound connections from the server.
In its research, Wiz also describes CVE-2026-82329 being exploited separately. However, the main finding in the notice concerns the CVE-2026-42018 and CVE-2026-42016 chain. Further details may come from possible indicators of compromise or updated guidance from JFrog or CISA, as well as forensic confirmation of additional incidents.
Sources
- Wiz Research – Wiz announced observed active exploitation of a two-flaw chain against self-hosted Artifactory and described subsequent persistence techniques.
- JFrog Security Advisories – JFrog confirms the nature of CVE-2026-42018, the scope of affected versions and the availability of fixes.
- BleepingComputer – Independently reports Wiz’s findings on the timing of the attacks, escalation to administrative privileges and deployment of a backdoor.
Verified and updated: 09/14/2026 06:22



