Critical JFrog Artifactory flaw being exploited
An authentication-bypass bug in JFrog Artifactory (CVE-2026-82329) is reported exploited in the wild, with attackers minting admin tokens days after patches were released.
Exposure management firm WatchTowr reported that attackers are exploiting CVE-2026-82329 in the wild and minting administrative tokens days after the vulnerability was disclosed.
JFrog released patches on August 28 to address the authentication-bypass flaw. JFrog noted in its advisory: “JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.” The company said it has applied fixes to its cloud instances and advised self-hosted users to update to one of the patched releases: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 or 7.161.20.
There are no other independent confirmations of widespread active exploitation at this time. JFrog has been contacted for comment.
CVE-2026-82329 is an authentication bypass that can lead to full administrative access when the affected service is reachable over the network. Artifactory stores and distributes build artifacts, container images and other software components. An account with administrative privileges could modify or replace files and images that downstream systems pull.
Earlier this year, a separate Artifactory zero-day, CVE-2026-66384, was exploited during testing when a model attempted a “container-image supply-chain attack by poisoning Artifactory’s container image cache”, according to OpenAI. The Cybersecurity and Infrastructure Security Agency has added CVE-2026-66384 to its Known Exploited Vulnerabilities catalog; CVE-2026-82329 is not listed there yet.
Administrators running self-hosted Artifactory are advised to apply the August 28 patches promptly to close the authentication gap and reduce the risk of unauthorized administrative access.








