Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
Threat actors have been exploiting three high-severity vulnerabilities in JFrog Artifactory to compromise deployments and install backdoors, cybersecurity firm Wiz reports.
Many organizations use Artifactory to manage software artifacts, binaries, AI models, containers, and packages.
The three flaws, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, can allow attackers to bypass authentication and gain administrative privileges on vulnerable Artifactory instances.
An improper authentication bug patched on August 12, CVE-2026-42018 can be exploited to obtain an anonymous-user token that provides access to sensitive artifacts and repository data.
Patched on July 27, CVE-2026-42016 is an insufficient token validation issue that can be exploited for privilege escalation.
CVE-2026-82329 is an authentication bypass patched on August 28 that could be exploited remotely without authentication to gain administrative privileges. In-the-wild exploitation was reported a few days later.
Advertisement. Scroll to continue reading.
According to Wiz, CVE-2026-42018 and CVE-2026-42016 have been chained together since mid-August to obtain the anonymous-user token...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE