Back to advisories

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipeline. Any organization running self-hosted Artifactory is at immediate risk of supply chain compromise.

CRITICALAdvisorySep 12, 2026
Action required
Immediately patch all self-hosted JFrog Artifactory instances to the latest patched version. Concurrently: audit admin token activity and user permission changes in the last 30 days, scan repositories for suspicious artifacts or modifications, and monitor for any shell command execution in Artifactory logs.
Affected products
JFrog ArtifactoryJFrogGroovy pluginsWizFastly