Attackers exploited JFrog Artifactory flaws to install backdoors

Three high-severity JFrog Artifactory vulnerabilities were exploited to bypass authentication, gain admin privileges and install persistent backdoors on self-hosted instances.

Cybersecurity firm Wiz reported attackers used three high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrator privileges and install persistent backdoors on self-hosted instances. Artifactory is used to store software artifacts, containers, AI models and packages. The affected flaws are CVE-2026-42016, CVE-2026-42018 and CVE-2026-82329. Because these flaws are already being exploited, organizations should treat remediation as a priority within their vulnerability management process rather than routine patching.

CVE-2026-42018, an improper authentication bug patched on August 12, can be used to mint an anonymous-user token that exposes repository data. CVE-2026-42016, patched on July 27, is an insufficient token validation issue that can be used to elevate that token to administrator-level access. Wiz reported multiple actors chained those two flaws between August 15 and September 8, 2026 to take control of self-hosted deployments.

CVE-2026-82329, an authentication bypass fixed on August 28, was exploited in early September. Exploitation of that flaw allowed attackers to exfiltrate configuration, create persistent admin accounts, mint tokens, extract cluster keys and enumerate assets. In some intrusions attackers attached their own SSH keys to accounts they created.

After gaining access, attackers installed malicious plugins to achieve arbitrary code execution, ran shell commands through plugin endpoints, dropped second-stage payloads and modified scripts to maintain access. Wiz documented multiple cases where attackers updated tooling after the initial compromise and left persistent admin users in place.

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-42018 and CVE-2026-42016 to its Known Exploited Vulnerabilities catalog on Friday, one week after adding CVE-2026-82329. Under Binding Operational Directive 26-04, federal agencies were given two weeks to patch affected systems.

JFrog has published fixed releases; organizations running self-managed Artifactory are advised to upgrade as soon as possible to one of the patched versions: 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28 or 7.111.21. Administrators should review logs and active accounts for unauthorized admin users, inspect installed plugins and rotate keys and tokens where compromise is suspected.

Articles by this author