Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
Three JFrog Artifactory flaws are being exploited to deploy backdoors and gain admin privileges.
Summary
Attackers are actively exploiting three high-severity vulnerabilities in JFrog Artifactory to compromise deployments, bypass authentication, and install backdoors. Two of the flaws, CVE-2026-42018 and CVE-2026-42016, have been chained together since mid-August to gain administrative privileges, while CVE-2026-82329 is being exploited for configuration exfiltration and persistent access. CISA has added these vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch.
Full text
Threat actors have been exploiting three high-severity vulnerabilities in JFrog Artifactory to compromise deployments and install backdoors, cybersecurity firm Wiz reports. Many organizations use Artifactory to manage software artifacts, binaries, AI models, containers, and packages. The three flaws, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, can allow attackers to bypass authentication and gain administrative privileges on vulnerable Artifactory instances. An improper authentication bug patched on August 12, CVE-2026-42018 can be exploited to obtain an anonymous-user token that provides access to sensitive artifacts and repository data. Patched on July 27, CVE-2026-42016 is an insufficient token validation issue that can be exploited for privilege escalation. CVE-2026-82329 is an authentication bypass patched on August 28 that could be exploited remotely without authentication to gain administrative privileges. In-the-wild exploitation was reported a few days later.Advertisement. Scroll to continue reading. According to Wiz, CVE-2026-42018 and CVE-2026-42016 have been chained together since mid-August to obtain the anonymous-user token and then use it to elevate privileges to administrator. “Between August 15 and September 8, 2026, we observed multiple actors chain CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances,” Wiz says. The hackers were seen deploying persistent admin accounts, installing malicious plugins to gain arbitrary code execution, running shell commands through the plugin endpoint, dropping second-stage payloads, and occasionally updating the scripts for continuous access. Multiple threat actors also started exploiting CVE-2026-82329 in the first week of September, for configuration exfiltration, persistent admin access, token minting, cluster key exfiltration, and asset enumeration. In some instances, the attackers were seen attaching their own SSH keys to the user accounts they created. On Friday, CISA added CVE-2026-42018 and CVE-2026-42016 to its KEV catalog, one week after it added CVE-2026-82329 to the list. In line with BOD 26-04, federal agencies were given two weeks to patch their vulnerable instances. All organizations are advised to update their self-managed Artifactory deployments to versions 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, or 7.111.21 as soon as possible. Related: GitLab Vulnerability Exploited One Day After Disclosure Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Related: PaperCut Flaws Exploited in AI-Powered Attacks Related: Critical NetScaler Vulnerability Exploited in Attacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Check Point Patches Critical VPN VulnerabilitiesSurfshark Systems Targeted by HackersPaperCut Flaws Exploited in AI-Powered AttacksCritical NetScaler Vulnerability Exploited in Attacks4.1 Million Impacted by AdaptHealth Data BreachNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft DefenderFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksHelmGuard Raises $7.3 Million for Agentic GRC and Security Latest News Telus Warns Customers of Account BreachesConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like AttacksAnthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch UpBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-DaysUsers in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic SaysPhishing Research Challenges Conventional Security Awareness TestingGitLab Vulnerability Exploited One Day After DisclosureIn Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveZero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.Patrick McKinney has joined Turing as Chief Information Security Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-42016
- cve — CVE-2026-42018
- cve — CVE-2026-82329