CVE Tools

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

The Hacker NewsBy The Hacker News

Reported exploitedJFrog Artifactory

Our summary

Wiz has confirmed active exploitation of a vulnerability chain in self-hosted JFrog Artifactory servers that allows attackers to gain administrator control. By combining an unauthenticated token disclosure flaw (CVE-2026-42018) with a privilege escalation bug (CVE-2026-42016), threat actors can swap anonymous tokens for administrative scope to deploy malicious plugins and establish command-and-control channels. This attack campaign occurred between August 15 and September 8, targeting systems that had not yet applied fixes released by JFrog.

Administrators should urgently verify their deployment status against JFrog's security advisories, as patching alone does not remove previously created attacker accounts or revoked tokens. While the chained flaws require specific version combinations, a separate critical authentication bypass (CVE-2026-82329, CVSS 9.8) was also exploited independently during this period, affecting up to version 7.161.20. Organizations must rotate join keys, audit unauthorized administrator accounts, and ensure all instances are updated to the latest fixed releases.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store