[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4nLFtQcjhYfe4whxJ97pfWOUZ6zSz2muOA7gv1x9GBc":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"ff165912-dd8d-4feb-b752-b9b45f225e4e","Artifactory flaws chained in attacks deploying backdoor malware","artifactory-flaws-chained-in-attacks-deploying-backdoor-malware-a9e03a","Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]","Threat actors are actively exploiting critical vulnerabilities in JFrog Artifactory, specifically CVE-2026-42018 and CVE-2026-42016, to bypass authentication and gain administrative privileges. Attackers are chaining these flaws to deploy a custom Rust backdoor on self-hosted Artifactory servers, with some instances compromised in under five minutes. Wiz reports that a significant percentage of Artifactory instances are vulnerable.","Attackers exploit Artifactory flaws to gain admin access and deploy Rust backdoor.","Artifactory flaws chained in attacks deploying backdoor malware By Bill Toulas September 11, 2026 12:29 PM 0 Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. A new report from cloud security company Wiz confirmed exploitation across multiple environments, including an exploit chain that combines CVE-2026-42018 and CVE-2026-42016. The third vulnerability is CVE-2026-82329, a critical authentication bypass that offensive security company watchTowr observed being exploited earlier this month to mint administrator tokens. According to Wiz, attackers exploit CVE-2026-42018 to obtain a JSON Web Token (JWT) belonging to an internal Artifactory anonymous user, even when anonymous access is disabled, with low privileges. Then they increase permissions to admin level by exploiting CVE-2026-42016, caused by insufficient token validation. Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token. The researchers note that in some cases the attacker took less than five minutes to create an administrator account. After creating admin accounts and generating long-lived access tokens, the attackers installed malicious Groovy plugins to execute arbitrary commands and established persistence by deploying a Rust-based backdoor. “Between August 15 and September 8, 2026, we observed multiple actors chain CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances,” Wiz says. “Across multiple cases, we observed a custom Rust backdoor with C2 capabilities being dropped.” In the next stage, the threat actor downloaded additional payloads into \u002Fdev\u002Fshm, \u002Ftmp, and \u002Fvar\u002Ftmp, uploaded webshells, stole Artifactory configuration data and cluster join keys, enumerated repositories, tokens, and users, and added their SSH keys to newly created accounts. Wiz warns that between 49% and 62% of reachable Artifactory instances are vulnerable to at least one of the three flaws. System administrators are recommended to upgrade immediately to one of the following Artifactory release versions or later: 7.111.21 7.117.28 7.125.20 7.133.29 7.146.38 7.161.20 After upgrading, investigate internet-exposed instances for unexpected token creation, rogue administrator accounts, suspicious plugin activity, and enumeration requests, and restrict access to trusted systems only. Wiz has listed indicators of compromise (IoCs) associated with the observed attacks to help defenders detect them quickly. BleepingComputer has contacted JFrog to confirm the reported activity, but we have not received a response as of publication. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Hackers exploit critical JFrog Artifactory flaw to forge admin tokensHackers target WordPress sites in miniOrange auth bypass attacksHackers exploit macOS Screen Sharing flaw to deploy Monero minerN-able warns of N-central auth bypass flaw exploited in attacksCheck Point warns of SmartConsole zero-day exploited in attacks","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fartifactory-flaws-chained-in-attacks-deploying-backdoor-malware\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2025\u002F03\u002F12\u002Fhacker.jpg","2026-09-11T16:29:44+00:00","2026-09-11T18:00:38.517581+00:00",9,[18,21,24],{"name":19,"type":20},"Artifactory","product",{"name":22,"type":23},"JFrog","vendor",{"name":25,"type":26},"JWT","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":27,"icon":29,"name":30,"slug":31},null,"Vulnerabilities","vulnerabilities",[33,38,40,45],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":39},{"id":27,"icon":29,"name":30,"slug":31},{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":46},{"id":47,"icon":29,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,55,58],{"type":52,"value":53,"context":54},"cve","CVE-2026-42018","Vulnerability used to obtain an internal Artifactory anonymous user JWT.",{"type":52,"value":56,"context":57},"CVE-2026-42016","Vulnerability used for insufficient token validation to increase permissions.",{"type":52,"value":59,"context":60},"CVE-2026-82329","Critical authentication bypass vulnerability observed being exploited."]