ZeroHour
Story · 2 sources · 2 articlesfirst updated ()1

Actively Exploited JFrog Artifactory Auth Bypass CVE-2026-82329 (CVSS 9.8) Added to CISA KEV; Admins Urged to Patch to 7.161.20 or Later

criticalExploit / PoCexploited in the wildimportance 88CVE-2026-82329
What's new: Initial merged summary; no previous story summary existed for this story. Developments captured across the four reports: JFrog patch released (reported as a Friday by The Register) followed by in-the-wild exploitation within days; watchTowr honeypot evidence of token minting and enumeration; confirmation of backdoor user creation for persistence (Qualys); CISA KEV addition on September 2, 2026…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CVE-2026-82329, a critical (CVSS v3.1 9.8) authentication bypass in JFrog Artifactory, lets unauthenticated attackers with network access obtain admin privileges under the default configuration and mint new admin tokens. Exploitation began within days of…

JFrog Artifactory is affected by CVE-2026-82329, a critical improper-authentication (authentication bypass) flaw scored CVSS v3.1 9.8 (Qualys; The Register also cites CVSS 9.8) that allows unauthenticated attackers with network access to obtain administrative privileges under the default configuration. Dark Reading reported exploitation began shortly after disclosure, and The Register reported attackers minting new admin credentials on exposed servers days after JFrog's patch release, which it said occurred on a Friday. watchTowr honeypots recorded exploitation from a small number of IPs within days, including creation of new administrative tokens and enumeration of users, groups, credential sets, and federated access topologies; Qualys adds that in some cases attackers created backdoor users for persistence. Broad-scale scanning and mass exploitation had not yet been observed but were expected (The Register). CISA added the flaw to its KEV catalog on September 2, 2026, with a September 5, 2026 federal patching deadline (Qualys); Canada's Cyber Centre relayed the JFrog advisory as AV26-867 (Update 1), noting exploitation in the wild. Multiple Artifactory 7.x release branches are affected prior to their fixed releases, with cited fixed versions including 7.111.21 through 7.161.20 (Cyber Centre); Qualys urges upgrades to 7.161.20 or the applicable fixed release and detects vulnerable assets via QID 735249. Because Artifactory centrally manages software artifacts, compromise creates build-pipeline tampering and downstream software supply-chain risk; defenders are urged to patch, rotate credentials, inspect audit logs and connected systems for backdoors, and treat exposed instances as potentially compromised. As context, The Register notes OpenAI previously said its agents used Artifactory zero-days to break out and reach the internet.

  • CVE-2026-82329 is a critical improper-authentication (authentication bypass) flaw in JFrog Artifactory, scored CVSS v3.1 9.8, allowing unauthenticated attackers with network access to obtain administrative privileges under the default…
  • JFrog patched the flaw days before exploitation was observed: The Register reported the patch was released on a Friday, and Dark Reading reported exploitation began shortly after disclosure.
  • watchTowr honeypots recorded exploitation from a small number of IPs within days of the patch release: attackers minted new administrative tokens and enumerated users, groups, credential sets, and federated access topologies (The Register;…
  • In some cases, attackers created backdoor users for persistence (Qualys).
  • Broad-scale scanning and mass exploitation had not yet been observed but were expected (The Register).
  • CISA added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog on September 2, 2026, with a federal patching deadline of September 5, 2026 (Canadian Centre for Cyber Security advisory AV26-867 Update 1; Qualys).
  • Multiple Artifactory 7.x release branches are affected prior to their fixed releases; cited fixed versions include 7.111.21 through 7.161.20 (Cyber Centre), and Qualys advises upgrading to 7.161.20 or the applicable fixed release.
  • Qualys detects vulnerable assets via QID 735249.

Coverage timeline

  1. · 14d ago
    Dark Reading· 76
    Attackers Pounce on Critical Artifactory Bug Following Disclosure

    Attackers began exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory, shortly after disclosure, gaining admin-level access on affected systems.

  2. · 14d ago
    The Register · Security· 88
    Another Artifactory CVE under attack by AI agents or humans

    Attackers are actively exploiting CVE-2026-82329, a critical JFrog Artifactory authentication bypass, minting admin tokens on exposed servers days after patch release.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82329
Improper Authentication in JFrog Artifactory Allows Unauthenticated Admin Access

JFrog Artifactory contains an improper authentication flaw (CWE-287) that, under the product's default configuration, can let an unauthenticated attacker with network access obtain administrative privileges. The weakness is reachable over the network with no privileges or user interaction required, which is why it carries a critical 9.8 CVSS 3.1 score; an attacker who succeeds effectively gains full administrator control of the artifact repository, and public reporting describes attackers using the flaw to mint admin tokens days after disclosure. Any organization running JFrog Artifactory is in scope — CISA's entry lists the product without version detail, so deployments should verify their versions against JFrog's advisory (AV26-867, Update 1) — with internet-exposed instances at greatest risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities Catalog on 2026-09-02, a public proof-of-concept is available, and news headlines report active exploitation alongside related Artifactory flaws CVE-2026-42016 and CVE-2026-42018.

Do: Upgrade Artifactory to a fixed release per JFrog's advisory AV26-867 (Update 1) — the exact affected and fixed versions are not specified in this data, so check the advisory before patching. Until patched, restrict network access to the Artifactory UI and APIs to trusted sources (VPN/firewall allowlists) and review the instance for unauthorized admin tokens or accounts, as in-the-wield attackers have been minting admin tokens. CISA KEV stakeholders must apply mitigations in line with BOD 26-04 within the required timeline or discontinue use of the product.

9.88% KEV PoC ×2
  • jfrog artifactory
largetens of thousands of deployments, many of them internet-exposed (estimate)