ZeroHour
Cyber Security Newspublished ()ingested Abinaya
Part of a story covered by 7 sources: “JFrog Artifactory Flaws Exploited for Admin Takeover and Rust Backdoors; All Three CVEs Added to CISA KEV” — merged summary and timeline →

JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control

criticalExploit / PoC exploited in the wildimportance 79CVE-2026-42016CVE-2026-42018CVE-2026-82329
AI summary · glm-5.3-flash

Wiz observed active exploitation of three JFrog Artifactory flaws used to mint admin tokens, deploy malicious plugins, and install Rust backdoors on self-hosted servers.

JFrog Artifactory flaws CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 are being actively exploited against self-hosted instances, enabling token exposure, token scope abuse, and a critical default-configuration authentication bypass. Wiz observed attackers chaining CVE-2026-42018 and CVE-2026-42016 from August 15 to September 8, 2026, creating persistent administrator accounts in under five minutes, deploying malicious Groovy plugins, and installing Rust-based backdoors. At disclosure, 67-69 percent of Wiz-monitored organizations ran vulnerable instances; fixed releases include 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 or later depending on branch.

  • CVE-2026-82329: unauthenticated admin token via /access/api/v1/registry/join
  • Attackers created rogue accounts like 0xterror and jfrog-distribution for persistence
  • 67% of organizations with Artifactory had a vulnerable instance at disclosure
  • Defenders should hunt for hits on aws/token, tokens, and registry/join endpoints

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-42016
Token Scope Validation Flaw Enables Privilege Escalation in JFrog Artifactory

JFrog Artifactory (Self-Hosted) versions before 7.133.11 fail to validate a token's scope, checking only the token's signature and issuer, which constitutes an incorrect authorization flaw (CWE-863). A remote, authenticated user with low privileges can obtain or present a token whose scope is never verified, bypassing authorization checks and escalating to higher privileges. Successful attackers gain administrative control of the Artifactory instance; in observed attacks this flaw has been chained with CVE-2026-42018 and CVE-2026-82329 to bypass authentication, take admin control, and deploy backdoor malware. Only self-hosted Artifactory deployments are within the stated affected scope. Exploitation is confirmed in the wild and the vulnerability was added to CISA's KEV catalog on 2026-09-11, although no public proof-of-concept code is known.

Do: Upgrade self-hosted Artifactory to version 7.133.11 or later immediately, in line with vendor instructions and CISA KEV/BOD 26-04 timelines. Audit issued tokens and logs for tokens carrying elevated scope granted to low-privilege users, and look for signs of compromise such as unexpected admin accounts or persistence, given reported backdoor deployments. Also patch CVE-2026-42018 and CVE-2026-82329, which attackers are chaining with this flaw.

8.8<1% KEV
  • JFrog Artifactory (Self-Hosted) All versions before 7.133.11
largetens of thousands of self-hosted instances (subset internet-exposed)
CVE-2026-42018
Improper Authentication in JFrog Artifactory Exposes Internal Anonymous Tokens

JFrog Artifactory contains an improper authentication flaw (CWE-287) in which the server may return its internal anonymous-user token to an unauthenticated caller, even on instances where anonymous access is disabled. An attacker triggers the issue by sending unauthenticated requests to the affected Artifactory interface over the network; the vector requires no privileges or user interaction and is of low complexity. Successful abuse yields the internal anonymous-user token, which can then be used to reach sensitive resources (such as repositories or artifacts) that should be protected when anonymous access is disabled, with high confidentiality impact but no integrity or availability impact. Any organization running an affected JFrog Artifactory deployment - particularly those relying on disabled anonymous access as a control - is affected, though only instances where the vulnerable endpoint is reachable are actually exposed. Exploitation has been reported in the wild as part of an ongoing Artifactory attack campaign alongside CVE-2026-42016 and CVE-2026-82329, although there is no public PoC and the flaw is not yet in the CISA KEV catalog.

Do: Upgrade Artifactory to the fixed release identified in JFrog's security advisory (JFrog is the assigning CNA; exact version numbers are not included in the available data). Until patched, restrict unauthenticated network access to Artifactory, verify the anonymous-access configuration, and review logs for unauthenticated requests that retrieved tokens or accessed sensitive resources. Because in-the-wild exploitation has been reported alongside CVE-2026-42016 and CVE-2026-82329, patch for all three and consider rotating internal/anonymous tokens and auditing artifact access.

7.5<1% KEV
  • JFrog Artifactory
large≈ tens of thousands of deployments (only the subset with anonymous access disabled and a reachable endpoint is affected)
CVE-2026-82329
Improper Authentication in JFrog Artifactory Allows Unauthenticated Admin Access

JFrog Artifactory contains an improper authentication flaw (CWE-287) that, under the product's default configuration, can let an unauthenticated attacker with network access obtain administrative privileges. The weakness is reachable over the network with no privileges or user interaction required, which is why it carries a critical 9.8 CVSS 3.1 score; an attacker who succeeds effectively gains full administrator control of the artifact repository, and public reporting describes attackers using the flaw to mint admin tokens days after disclosure. Any organization running JFrog Artifactory is in scope — CISA's entry lists the product without version detail, so deployments should verify their versions against JFrog's advisory (AV26-867, Update 1) — with internet-exposed instances at greatest risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities Catalog on 2026-09-02, a public proof-of-concept is available, and news headlines report active exploitation alongside related Artifactory flaws CVE-2026-42016 and CVE-2026-42018.

Do: Upgrade Artifactory to a fixed release per JFrog's advisory AV26-867 (Update 1) — the exact affected and fixed versions are not specified in this data, so check the advisory before patching. Until patched, restrict network access to the Artifactory UI and APIs to trusted sources (VPN/firewall allowlists) and review the instance for unauthorized admin tokens or accounts, as in-the-wield attackers have been minting admin tokens. CISA KEV stakeholders must apply mitigations in line with BOD 26-04 within the required timeline or discontinue use of the product.

9.88% KEV PoC ×2
  • jfrog artifactory
largetens of thousands of deployments, many of them internet-exposed (estimate)

Indicators of compromiseAll →

TypeIndicatorContext
domaingitclone.org.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash
sha1513a907b69edffc3cb77a494da395178d21ef9bdmtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a494da395178d21ef9bd Account 0xterror , svc_[a-zA-Z0-9]{8} , Nxploited_[a-zA-Z0-
urlhttp://3.88.162[]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Hash /tmp/.z — 513a907b69edffc3cb77a4
urlhttp://log.gitclone[[.]88 , 137.184.111[.]69 , 64.207.232[.]6:8443 Payload URLs hxxp://log.gitclone[.]org:45678/smtp , hxxp://3.88.162[.]79:36789/smtp File / Ha
Full article594 words · extracted from cybersecuritynews.com · click to collapse

An active exploitation of three JFrog Artifactory vulnerabilities that attackers are using to bypass authentication, elevate privileges, and take administrative control of exposed servers.

The flaws, tracked as CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, affect multiple Artifactory release branches and create a serious supply-chain security risk.

Attackers have already targeted self-hosted Artifactory deployments, creating persistent administrator accounts, deploying malicious Groovy plugins, executing shell commands, and installing Rust-based backdoors.

Since Artifactory commonly stores software packages, credentials, repository metadata, and CI/CD integrations, a successful compromise could give attackers a route into broader development and cloud environments.

CVE-2026-42018 is an authentication flaw that can expose an internal anonymous-user token to an unauthenticated remote requester, even when anonymous access is disabled. The token may provide access to resources available to Artifactory’s internal anonymous identity.

CVE-2026-42016 is a token scope-validation weakness. Artifactory validates a token’s signature and issuer but may fail to enforce its authorized scope correctly. An attacker can abuse a valid low-privilege token to request elevated permissions.

JFrog Artifactory Vulnerabilities Actively Exploited

Wiz observed attackers chaining CVE-2026-42018 and CVE-2026-42016 between August 15 and September 8, 2026. The activity began with a POST request to /access/api/v1/aws/token/, including a trailing slash, which returned an anonymous JWT token.

Critical Artifactory Authentication Bypass Flaw ( source : wiz )
Critical Artifactory Authentication Bypass Flaw ( source: Wiz )

The attackers then sent the token to /access/api/v1/tokens to generate an administrator-scoped token. Subsequent actions appeared in logs as token: anonymous, despite possessing administrative authority.

In several cases, attackers created a persistent administrator account in less than five minutes using endpoints such as /api/security/users/.

They also installed malicious Groovy plugins through Artifactory’s native plugin framework, allowing arbitrary server-side command execution.

Payload droppers downloaded binaries into writable locations including /tmp, /dev/shm, and /var/tmp, then established command-and-control communications.

The third flaw, CVE-2026-82329, is a critical authentication bypass affecting Artifactory installations using the default configuration. An unauthenticated attacker can send a POST request to /access/api/v1/registry/join and potentially receive an administrator-scoped token.

Wiz observed exploitation from September 1 through September 8, followed by configuration theft, user and repository enumeration, token creation, and theft of cluster join keys.

Threat actors also created accounts named jfrog-distribution, jfrog-insight, repo-service, backup-service, ldap_admin, and 0xterror. These accounts can blend into normal service identities and provide long-term access after the initial vulnerability is patched.

Cloud exposure remains significant. Wiz found that 67 percent of organizations running Artifactory had at least one vulnerable instance when CVE-2026-42016 was disclosed on July 27.

JFrog Artifactory Exploitation IOCs:

Type IOCs
IP / C293.104.155[.]133, 146.19.216[.]120, 185.190.58[.]172, 45.61.176[.]88, 137.184.111[.]69, 64.207.232[.]6:8443
Payload URLshxxp://log.gitclone[.]org:45678/smtp, hxxp://3.88.162[.]79:36789/smtp
File / Hash/tmp/.z513a907b69edffc3cb77a494da395178d21ef9bd
Account0xterror, svc_[a-zA-Z0-9]{8}, Nxploited_[a-zA-Z0-9]{3}

For CVE-2026-42018, 69 percent were vulnerable at disclosure, while CVE-2026-82329 affected 67 percent of organizations when published on August 28. Remediation for the critical authentication bypass was faster, but 49 percent of organizations remained exposed two weeks later.

Organizations should immediately identify all Artifactory instances, prioritize internet-facing deployments, and upgrade to fixed releases. Fixed versions include 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 or later, depending on the affected vulnerability and release branch.

Security teams should hunt for successful requests to /access/api/v1/aws/token/, /access/api/v1/tokens, and /access/api/v1/registry/join.

They should also investigate unexpected privileged activity by anonymous or low-privilege identities, newly created administrator accounts, plugin deployments, token minting, configuration exports, and unusual outbound connections from Artifactory servers.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/jfrog-artifactory-vulnerabilities-actively-exploited/