ZeroHour
Story · 1 source · 1 articlefirst updated ()

CISA adds actively exploited JFrog Artifactory authentication flaw CVE-2026-82329 (CVSS 9.8) to KEV catalog

criticalExploit / PoCexploited in the wildimportance 84CVE-2026-82329
What's new: First merged summary for this story. Establishes: KEV addition of CVE-2026-82329 (September 2, 2026) with a September 5, 2026 federal deadline; confirmed in-the-wild exploitation with observed attacker behavior (token minting, environment enumeration, backdoor user creation); affected scope across multiple Artifactory 7.x branches with named fixed releases (7.161.20; branch fixes cited as…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CISA added the actively exploited improper authentication flaw CVE-2026-82329 in JFrog Artifactory (CVSS v3.1 9.8) to its Known Exploited Vulnerabilities catalog on September 2, 2026, with a federal patch deadline of September 5, 2026. The flaw lets…

CISA added CVE-2026-82329, a critical improper authentication flaw in JFrog Artifactory, to its Known Exploited Vulnerabilities catalog on September 2, 2026, setting a federal patching deadline of September 5, 2026. The CVSS v3.1 9.8 flaw allows unauthenticated attackers with network access to obtain administrative privileges under the default configuration. WatchTowr honeypot data shows attackers minting administrator tokens, enumerating users, groups, and federated access topologies, and in some cases creating backdoor users for persistence. Canada's Cyber Centre (advisory AV26-867, Update 1, September 2, 2026) relays the JFrog security advisory and cites open-source reporting that the flaw is being exploited in the wild. Multiple Artifactory 7.x release branches are affected prior to the listed fixed releases: Qualys names 7.161.20 as a fixed version, while Canada's advisory describes affected versions as prior to fixed releases spanning 7.111.21 through 7.161.20. Qualys detects vulnerable assets via QID 735249. Users and administrators should apply the available updates for their release branch.

  • CVE-2026-82329 is a critical improper authentication flaw in JFrog Artifactory, scored CVSS v3.1 9.8, allowing unauthenticated attackers with network access to gain administrative privileges under the default configuration.
  • CISA added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog on September 2, 2026, with a federal patching deadline of September 5, 2026.
  • Exploitation has been observed in the wild; WatchTowr honeypots recorded attackers minting administrator tokens, enumerating users, groups, and federated access topologies, and creating backdoor users for persistence.
  • Multiple Artifactory 7.x release branches are affected prior to fixed releases; Qualys identifies 7.161.20 as a fixed version, and Canada's advisory cites fixed versions such as 7.111.21 through 7.161.20.
  • Canada's Cyber Centre advisory AV26-867 (Update 1, published 2026-09-02) relays the JFrog security advisory and urges prompt patching.
  • Qualys detects vulnerable assets via QID 735249.

Coverage timeline

  1. · 13d ago
    Canadian Centre for Cyber Security· 78
    JFrog security advisory (AV26-867) – Update 1

    CISA added actively exploited CVE-2026-82329 in JFrog Artifactory to its KEV catalog; administrators of affected versions should patch.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82329
Improper Authentication in JFrog Artifactory Allows Unauthenticated Admin Access

JFrog Artifactory contains an improper authentication flaw (CWE-287) that, under the product's default configuration, can let an unauthenticated attacker with network access obtain administrative privileges. The weakness is reachable over the network with no privileges or user interaction required, which is why it carries a critical 9.8 CVSS 3.1 score; an attacker who succeeds effectively gains full administrator control of the artifact repository, and public reporting describes attackers using the flaw to mint admin tokens days after disclosure. Any organization running JFrog Artifactory is in scope — CISA's entry lists the product without version detail, so deployments should verify their versions against JFrog's advisory (AV26-867, Update 1) — with internet-exposed instances at greatest risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities Catalog on 2026-09-02, a public proof-of-concept is available, and news headlines report active exploitation alongside related Artifactory flaws CVE-2026-42016 and CVE-2026-42018.

Do: Upgrade Artifactory to a fixed release per JFrog's advisory AV26-867 (Update 1) — the exact affected and fixed versions are not specified in this data, so check the advisory before patching. Until patched, restrict network access to the Artifactory UI and APIs to trusted sources (VPN/firewall allowlists) and review the instance for unauthorized admin tokens or accounts, as in-the-wield attackers have been minting admin tokens. CISA KEV stakeholders must apply mitigations in line with BOD 26-04 within the required timeline or discontinue use of the product.

9.88% KEV PoC ×2
  • jfrog artifactory
largetens of thousands of deployments, many of them internet-exposed (estimate)