JFrog security advisory (AV26-867) – Update 1
CISA added actively exploited CVE-2026-82329 in JFrog Artifactory to its KEV catalog; administrators of affected versions should patch.
Canada's Cyber Centre (advisory AV26-867, Update 1) relays a JFrog security advisory covering Artifactory, where open-source reporting indicates CVE-2026-82329 is being exploited in the wild. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 2, 2026. Multiple Artifactory release lines prior to fixed versions (e.g., prior to 7.111.21 through 7.161.20) are affected; users and administrators are urged to apply available updates.
- CISA added CVE-2026-82329 to its KEV database on September 2, 2026; exploitation observed in the wild.
- Affected Artifactory versions span many 7.x branches prior to listed fixed releases; patch promptly.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82329 | Improper Authentication in JFrog Artifactory Allows Unauthenticated Admin Access JFrog Artifactory contains an improper authentication flaw (CWE-287) that, under the product's default configuration, can let an unauthenticated attacker with network access obtain administrative privileges. The weakness is reachable over the network with no privileges or user interaction required, which is why it carries a critical 9.8 CVSS 3.1 score; an attacker who succeeds effectively gains full administrator control of the artifact repository, and public reporting describes attackers using the flaw to mint admin tokens days after disclosure. Any organization running JFrog Artifactory is in scope — CISA's entry lists the product without version detail, so deployments should verify their versions against JFrog's advisory (AV26-867, Update 1) — with internet-exposed instances at greatest risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities Catalog on 2026-09-02, a public proof-of-concept is available, and news headlines report active exploitation alongside related Artifactory flaws CVE-2026-42016 and CVE-2026-42018. Do: Upgrade Artifactory to a fixed release per JFrog's advisory AV26-867 (Update 1) — the exact affected and fixed versions are not specified in this data, so check the advisory before patching. Until patched, restrict network access to the Artifactory UI and APIs to trusted sources (VPN/firewall allowlists) and review the instance for unauthorized admin tokens or accounts, as in-the-wield attackers have been minting admin tokens. CISA KEV stakeholders must apply mitigations in line with BOD 26-04 within the required timeline or discontinue use of the product. | 9.8 | 8% | KEV PoC ×2 |
| largetens of thousands of deployments, many of them internet-exposed (estimate) |
Full article112 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-867
Date: September 1, 2026
Updated: September 2, 2026
As of August 28, 2026, JFrog is affected by a vulnerability in the following product:
Artifactory
Prior to 7.111.21
Prior to 7.117.28
Prior to 7.125.20
Prior to 7.133.29
Prior to 7.146.38
Prior to 7.161.20
Open-source reporting indicates that CVE-2026-82329 related to JFrog Artifactory is being exploited in the wild.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Update 1
On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-82329 to their Known Exploited Vulnerabilities (KEV) Database.
Artifactory Self-Managed Releases
JFrog Security Advisories
CISA KEV: CVE-2026-82329
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/jfrog-security-advisory-av26-867