ZeroHour
Dark Readingpublished ()ingested Jai Vijayan
Part of a story covered by 2 sources: “Actively Exploited JFrog Artifactory Auth Bypass CVE-2026-82329 (CVSS 9.8) Added to CISA KEV; Admins Urged to Patch to 7.161.20 or Later” — merged summary and timeline →

Attackers Pounce on Critical Artifactory Bug Following Disclosure

criticalExploit / PoC exploited in the wildimportance 76CVE-2026-82329
AI summary · glm-5.3-flash

Attackers began exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory, shortly after disclosure, gaining admin-level access on affected systems.

CVE-2026-82329 is a critical authentication bypass in JFrog's Artifactory repository manager that enables attackers to gain admin-level access on affected systems. Exploitation started soon after the flaw's disclosure. Artifactory is widely used to manage software artifacts, making compromised instances a software supply chain risk.

  • CVE-2026-82329 is an authentication bypass in JFrog Artifactory enabling admin-level access.
  • Exploitation began shortly after disclosure, per Dark Reporting on the flaw.
  • Compromise of central artifact repositories creates software supply chain tampering risk.
VendorsJFrog
ProductsArtifactory

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82329
Improper Authentication in JFrog Artifactory Allows Unauthenticated Admin Access

JFrog Artifactory contains an improper authentication flaw (CWE-287) that, under the product's default configuration, can let an unauthenticated attacker with network access obtain administrative privileges. The weakness is reachable over the network with no privileges or user interaction required, which is why it carries a critical 9.8 CVSS 3.1 score; an attacker who succeeds effectively gains full administrator control of the artifact repository, and public reporting describes attackers using the flaw to mint admin tokens days after disclosure. Any organization running JFrog Artifactory is in scope — CISA's entry lists the product without version detail, so deployments should verify their versions against JFrog's advisory (AV26-867, Update 1) — with internet-exposed instances at greatest risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities Catalog on 2026-09-02, a public proof-of-concept is available, and news headlines report active exploitation alongside related Artifactory flaws CVE-2026-42016 and CVE-2026-42018.

Do: Upgrade Artifactory to a fixed release per JFrog's advisory AV26-867 (Update 1) — the exact affected and fixed versions are not specified in this data, so check the advisory before patching. Until patched, restrict network access to the Artifactory UI and APIs to trusted sources (VPN/firewall allowlists) and review the instance for unauthorized admin tokens or accounts, as in-the-wield attackers have been minting admin tokens. CISA KEV stakeholders must apply mitigations in line with BOD 26-04 within the required timeline or discontinue use of the product.

9.88% KEV PoC ×2
  • jfrog artifactory
largetens of thousands of deployments, many of them internet-exposed (estimate)
Full article

CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at darkreading.com.