NPM · SEPTEMBER 2026 · CONFIRMED

JFrog Artifactory Under Attack: Critical Vulnerabilities Exploited

Severity
CRITICAL
Affected component
jfrog artifactory (npm)
Patched version
Not yet available
CVE-2026-42016CVE-2026-42018CVE-2026-82329

Attackers are exploiting three critical vulnerabilities in JFrog Artifactory to bypass authentication and gain administrative control. Users of JFrog Artifactory are advised to take immediate action.

What happened

Attackers have been observed chaining CVE-2026-42018 and CVE-2026-42016 to obtain an internal anonymous-user token and then escalate privileges to administrator level. CVE-2026-82329, a critical authentication bypass, is also being exploited to mint administrator tokens. These exploits allow attackers to deploy backdoors on vulnerable self-hosted servers.

The attacks were first flagged on September 10, 2026, and confirmed the next day. JFrog has released patches for these vulnerabilities, but the exact version ranges affected have not been officially published. It is crucial for users to upgrade to the latest version of JFrog Artifactory and review their access controls.

According to cloud security company Wiz, the attack pattern involves sending an unauthenticated request to a token endpoint, receiving an internal anonymous-user token, and then exchanging it for an administrator-scoped token. This process can be completed in under five minutes, highlighting the urgency for mitigation.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If jfrog artifactory is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using JFrog Artifactory, you may be affected. The exact version ranges are not yet officially published, so it is recommended to upgrade to the latest version as a precaution.

What should I do right now?

Upgrade to the latest version of JFrog Artifactory and review your access controls. Monitor your logs for any suspicious activity.

Has this been exploited in the wild?

Yes, these vulnerabilities have been actively exploited in the wild to gain administrative control and deploy backdoors.

Sources

Join the 0Day waitlist →

← Back to all threats