OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised
Attackers breached OpenInfra Europe's JFrog Artifactory via CVE-2026-82329, potentially compromising downloaded packages.
OpenInfra Europe said its self-hosted JFrog Artifactory at artifactory.nordix.org was compromised on August 31, 2026, and discovered on September 15 after a legitimate user was denied access. Unauthenticated attackers exploited CVE-2026-82329, an authentication bypass disclosed on August 28 and added to CISA's KEV catalog on September 2, to obtain admin privileges. Anyone who downloaded artifacts between August 28 and September 15 should stop using them and treat them as potentially compromised. The system was isolated, and the full impact is still undetermined.
- Artifactory at artifactory.nordix.org was compromised on August 31, 2026.
- CVE-2026-82329 authentication bypass gave unauthenticated attackers admin access.
- CISA added the flaw to KEV on September 2 after exploitation began.
- Discard packages downloaded from August 28 through September 15, 2026.
- Impact remains undetermined after the host was isolated.
Vulnerabilities mentionedAll →
- CVE-2026-823299.814%Improper Authentication in JFrog Artifactory Allows Unauthenticated Admin Accesspublished · jfrog artifactory KEV PoC ×2
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article302 words · extracted from helpnetsecurity.com · click to collapse
Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage.
OpenInfra Europe’s security incident notice
“Anyone who downloaded or installed artifacts from https://artifactory.nordix.org/ from August 28 and September 15, 2026 should immediately stop using them, remove them from their pipelines, and treat these packages as potentially compromised,” the message says.
Compromise through CVE-2026-82329
The OpenInfra Foundation is part of the non-profit Linux Foundation. It hosts and supports open source projects for running cloud and datacenter infrastructure. (Its best-known project is OpenStack, the open source platform for building private and public clouds.)
JFrog Artifactory is a binary repository manager that’s used for storing and serving the build outputs and dependencies that software development teams use. Organizations can self-host it or choose to go the Software-as-a-Service route.
According to the security notice, the compromised instance was running a vulnerable JFrog Artifactory version, which allowed unauthenticated attackers to exploit CVE-2026-82329, an authentication bypass vulnerability, to gain access to the instance and obtain admin privileges (and thus the capability to tamper with the deployment and the artifacts, credentials and integrations it manages.)
CVE-2026-82329 was publicly disclosed on August 28, 2026, and was added to CISA’s Known Exploited Vulnerabilities catalog on September 2.
According to various sources, in-the-wild exploitation began on August 31.
OpenInfra Europe says that the compromise of their Artifactory instance happened on that day, but that the breach was discovered on September 15, “after a legitimate user was denied access.”
The affected system was immediately isolated and investigation began, it added, but the full scope and impact of the incident is still undetermined.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
