CVE Tools

Attackers Pounce on Critical Artifactory Flaw Following Disclosure

Dark ReadingBy Jai Vijayan

Reported exploitedJFrog Artifactory

Our summary

Threat actors have begun active exploitation of CVE-2026-82329, a critical authentication bypass vulnerability in JFrog Artifactory, just days after its public disclosure. With a CVSS score of 9.8, this flaw enables unauthenticated attackers to gain administrative privileges on self-hosted deployments, potentially compromising software repositories and build artifacts. While JFrog clarified that this incident is distinct from recent attacks involving OpenAI and Hugging Face, watchTowr telemetry confirms attackers are already minting admin tokens and enumerating system details. Organizations using affected versions must urgently patch their systems and rotate credentials, as Internet-exposed instances should be treated as compromised.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store