Threat Intelligence

Hackers Chain Two JFrog Artifactory Bugs to Seize Admin Control and Plant Backdoors

The Hacker News · 11 Sept 2026
Key Takeaway Australian small businesses using self-hosted JFrog Artifactory should confirm they are running the latest patched versions and review admin account and access logs for unexplained anonymous activity.

Security firm Wiz has reported a wave of attacks between 15 August and 8 September targeting self-hosted JFrog Artifactory servers, the repository many software teams rely on to pull code during build pipelines. The attackers chained two separate vulnerabilities that, on their own, do not grant administrator access, but together allowed them to escalate from an anonymous request to full administrator control in as little as five minutes.

The method involved obtaining a token for an anonymous internal account and exchanging it for one with administrator privileges. Because this elevated token retained the anonymous username, malicious actions appeared in logs as generic anonymous activity rather than under a named account, making detection harder. Once inside, attackers created hidden administrator accounts, installed malicious plugins to run code on the server, executed shell commands, and in some cases deployed a custom backdoor with remote command capabilities. JFrog had already released patches for both flaws before the attacks began, meaning only servers that had not applied the updates were exposed.

Wiz also flagged a third, separate Artifactory vulnerability being exploited between 1 and 8 September, which could affect even servers running newer software branches. This means patch status alone may not guarantee safety, and organisations should check all known advisories carefully.

Key Takeaway: Australian small businesses using self-hosted JFrog Artifactory should confirm they are running the latest patched versions and review admin account and access logs for unexplained anonymous activity.

JFrog Artifactory software supply chain vulnerability management backdoor DevOps security
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.