CVE Tools

Artifactory flaws chained in attacks deploying backdoor malware

BleepingComputerBy Bill Toulas

Reported exploitedJFrog Artifactory

Our summary

Threat actors are actively chaining critical and high-severity vulnerabilities in JFrog Artifactory to establish persistence on self-hosted servers. The attack sequence combines CVE-2026-42018 and CVE-2026-42016 to escalate privileges from an anonymous user to an administrator, a process that can be completed in under five minutes. Following privilege escalation, attackers install malicious Groovy plugins and deploy a custom Rust-based backdoor capable of command-and-control operations.

Wiz research also highlights CVE-2026-82329, a separate critical authentication bypass observed in the wild, which allows the forging of administrative tokens. With up to 62% of reachable instances vulnerable, JFrog recommends immediate upgrades to versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20 to mitigate these risks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store