CISA adds actively exploited JFrog Artifactory authentication flaw CVE-2026-82329 (CVSS 9.8) to KEV catalog
CISA added the actively exploited improper authentication flaw CVE-2026-82329 in JFrog Artifactory (CVSS v3.1 9.8) to its Known Exploited Vulnerabilities catalog on September 2, 2026, with a federal patch deadline of September 5, 2026. The flaw lets…
CISA added CVE-2026-82329, a critical improper authentication flaw in JFrog Artifactory, to its Known Exploited Vulnerabilities catalog on September 2, 2026, setting a federal patching deadline of September 5, 2026. The CVSS v3.1 9.8 flaw allows unauthenticated attackers with network access to obtain administrative privileges under the default configuration. WatchTowr honeypot data shows attackers minting administrator tokens, enumerating users, groups, and federated access topologies, and in some cases creating backdoor users for persistence. Canada's Cyber Centre (advisory AV26-867, Update 1, September 2, 2026) relays the JFrog security advisory and cites open-source reporting that the flaw is being exploited in the wild. Multiple Artifactory 7.x release branches are affected prior to the listed fixed releases: Qualys names 7.161.20 as a fixed version, while Canada's advisory describes affected versions as prior to fixed releases spanning 7.111.21 through 7.161.20. Qualys detects vulnerable assets via QID 735249. Users and administrators should apply the available updates for their release branch.
- CVE-2026-82329 is a critical improper authentication flaw in JFrog Artifactory, scored CVSS v3.1 9.8, allowing unauthenticated attackers with network access to gain administrative privileges under the default configuration.
- CISA added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog on September 2, 2026, with a federal patching deadline of September 5, 2026.
- Exploitation has been observed in the wild; WatchTowr honeypots recorded attackers minting administrator tokens, enumerating users, groups, and federated access topologies, and creating backdoor users for persistence.
- Multiple Artifactory 7.x release branches are affected prior to fixed releases; Qualys identifies 7.161.20 as a fixed version, and Canada's advisory cites fixed versions such as 7.111.21 through 7.161.20.
- Canada's Cyber Centre advisory AV26-867 (Update 1, published 2026-09-02) relays the JFrog security advisory and urges prompt patching.
- Qualys detects vulnerable assets via QID 735249.
Coverage timelineoldest first · each row is one article
- · 13d agoJFrog security advisory (AV26-867) – Update 1
Canadian Centre for Cyber Security· 78
CISA added actively exploited CVE-2026-82329 in JFrog Artifactory to its KEV catalog; administrators of affected versions should patch.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82329 | Improper Authentication in JFrog Artifactory Allows Unauthenticated Admin Access JFrog Artifactory contains an improper authentication flaw (CWE-287) that, under the product's default configuration, can let an unauthenticated attacker with network access obtain administrative privileges. The weakness is reachable over the network with no privileges or user interaction required, which is why it carries a critical 9.8 CVSS 3.1 score; an attacker who succeeds effectively gains full administrator control of the artifact repository, and public reporting describes attackers using the flaw to mint admin tokens days after disclosure. Any organization running JFrog Artifactory is in scope — CISA's entry lists the product without version detail, so deployments should verify their versions against JFrog's advisory (AV26-867, Update 1) — with internet-exposed instances at greatest risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities Catalog on 2026-09-02, a public proof-of-concept is available, and news headlines report active exploitation alongside related Artifactory flaws CVE-2026-42016 and CVE-2026-42018. Do: Upgrade Artifactory to a fixed release per JFrog's advisory AV26-867 (Update 1) — the exact affected and fixed versions are not specified in this data, so check the advisory before patching. Until patched, restrict network access to the Artifactory UI and APIs to trusted sources (VPN/firewall allowlists) and review the instance for unauthorized admin tokens or accounts, as in-the-wield attackers have been minting admin tokens. CISA KEV stakeholders must apply mitigations in line with BOD 26-04 within the required timeline or discontinue use of the product. | 9.8 | 8% | KEV PoC ×2 |
| largetens of thousands of deployments, many of them internet-exposed (estimate) |