JFrog Artifactory Under Attack: Critical Vulnerabilities Exploited
- Severity
- CRITICAL
- Affected component
- jfrog artifactory (npm)
- Patched version
- Not yet available
Attackers are exploiting three critical vulnerabilities in JFrog Artifactory to bypass authentication and gain administrative control. Users of JFrog Artifactory are advised to take immediate action.
What happened
Attackers have been observed chaining CVE-2026-42018 and CVE-2026-42016 to obtain an internal anonymous-user token and then escalate privileges to administrator level. CVE-2026-82329, a critical authentication bypass, is also being exploited to mint administrator tokens. These exploits allow attackers to deploy backdoors on vulnerable self-hosted servers.
The attacks were first flagged on September 10, 2026, and confirmed the next day. JFrog has released patches for these vulnerabilities, but the exact version ranges affected have not been officially published. It is crucial for users to upgrade to the latest version of JFrog Artifactory and review their access controls.
According to cloud security company Wiz, the attack pattern involves sending an unauthenticated request to a token endpoint, receiving an internal anonymous-user token, and then exchanging it for an administrator-scoped token. This process can be completed in under five minutes, highlighting the urgency for mitigation.
What to do about it
- Upgrade to the latest version of JFrog Artifactory immediately.
- Review and strengthen your access controls to prevent unauthorized administrative actions.
- Monitor your logs for any suspicious activity, particularly actions logged under token:anonymous.
- Consult the primary sources for the most up-to-date information on patches and affected versions.
- No official fix version range has been published yet. Monitor the sources below for updates.
How 0Day would have caught this
jfrog artifactory is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using JFrog Artifactory, you may be affected. The exact version ranges are not yet officially published, so it is recommended to upgrade to the latest version as a precaution.
What should I do right now?
Upgrade to the latest version of JFrog Artifactory and review your access controls. Monitor your logs for any suspicious activity.
Has this been exploited in the wild?
Yes, these vulnerabilities have been actively exploited in the wild to gain administrative control and deploy backdoors.
Sources
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
- Artifactory flaws chained in attacks deploying backdoor malware
- Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
- More JFrog Artifactory bugs under attack, and all 3 have patches
- Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329