[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:attackers-chain-jfrog-artifactory-flaws-to-gain-admin-control-and-plant-backdoor-mtxoou9o":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":15,"action_required":21,"article_ids":22,"ioc_summary":24,"source_urls":25,"status":27,"expires_at":28,"created_at":29,"updated_at":30,"articles":31},"2f9cfaa6-7b78-44ea-aa76-7c57404ff3d1","Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors","attackers-chain-jfrog-artifactory-flaws-to-gain-admin-control-and-plant-backdoor-mtxoou9o","Attackers are chaining multiple JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) to escalate from anonymous users to administrator control on self-hosted instances. This grants them ability to plant backdoors and execute arbitrary shell commands in your build pipeline. Any organization running self-hosted Artifactory is at immediate risk of supply chain compromise.","critical","advisory",[12,13,14],"CVE-2026-42018","CVE-2026-42016","CVE-2026-82329",[16,17,18,19,20],"JFrog Artifactory","JFrog","Groovy plugins","Wiz","Fastly","Immediately patch all self-hosted JFrog Artifactory instances to the latest patched version. Concurrently: audit admin token activity and user permission changes in the last 30 days, scan repositories for suspicious artifacts or modifications, and monitor for any shell command execution in Artifactory logs.",[23],"ca1b89e9-a038-4de8-ac0e-cd729a9f25fd",null,[26],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fattackers-chain-jfrog-artifactory-flaws.html","active","2026-09-14T01:05:42.78+00:00","2026-09-12T01:05:51.698107+00:00","2026-09-12T01:06:33.222233+00:00",[32],{"id":23,"title":6,"url":26}]