JFrog Artifactory is being actively targeted through three high-severity vulnerabilities that attackers are chaining to bypass authentication, obtain administrative privileges, and deploy persistent backdoors. Between August 15 and September 8, 2026, multiple threat actors were observed exploiting CVE-2026-42018 and CVE-2026-42016 together, while CVE-2026-82329 was exploited separately for administrative access and configuration theft.
CVE-2026-42018: An improper authentication vulnerability that can allow attackers to obtain an anonymous-user token and access sensitive Artifactory artifacts and repository information. Attackers have used this token as the first stage of a broader privilege-escalation chain.
CVE-2026-42016: An insufficient token-validation vulnerability that can be exploited to escalate privileges. Threat actors chained it with CVE-2026-42018 to elevate access from the anonymous-user context to administrator privileges.
CVE-2026-82329: An authentication-bypass vulnerability that can be exploited remotely without authentication to obtain administrative access. Attackers have used it for configuration exfiltration, persistent administrator access, token creation, cluster-key theft, and asset enumeration.[/subscribe_to_unlock_form]
JFrog Artifactory is being actively targeted through three high-severity vulnerabilities that attackers are chaining to bypass authentication, obtain administrative privileges, and deploy persistent backdoors. Between August 15 and September 8, 2026, multiple threat actors were observed exploiting CVE-2026-42018 and CVE-2026-42016 together, while CVE-2026-82329 was exploited separately for administrative access and configuration theft.
CVE-2026-42018: An improper authentication vulnerability that can allow attackers to obtain an anonymous-user token and access sensitive Artifactory artifacts and repository information. Attackers have used this token as the first stage of a broader privilege-escalation chain.
CVE-2026-42016: An insufficient token-validation vulnerability that can be exploited to escalate privileges. Threat actors chained it with CVE-2026-42018 to elevate access from the anonymous-user context to administrator privileges.
CVE-2026-82329: An authentication-bypass vulnerability that can be exploited remotely without authentication to obtain administrative access. Attackers have used it for configuration exfiltration, persistent administrator access, token creation, cluster-key theft, and asset enumeration.[emaillocker id="1283"]
Following successful exploitation, attackers were observed creating persistent administrator accounts, installing malicious Artifactory plugins for arbitrary code execution, executing shell commands through plugin endpoints, deploying second-stage payloads, modifying scripts for continued access, and attaching their own SSH keys to newly created accounts.
We recommend you to update Artifactory deployments to 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, or 7.111.21, as applicable to the deployment branch.
The following reports contain further technical details:
[/emaillocker]