Hackers Race to Exploit Critical JFrog Artifactory Bug Just Days After Patch Release
Security researchers at watchTowr have detected active exploitation of CVE-2026-82329, a critical authentication bypass vulnerability in JFrog Artifactory that carries a near-maximum CVSS score of 9.8. The flaw allows attackers to mint administrative tokens, effectively giving them full control over affected systems under default configurations.
What makes this incident particularly concerning is the speed of exploitation. Attackers began targeting vulnerable systems just days after the vulnerability was publicly disclosed and a patch was made available, underscoring how quickly threat actors weaponise newly published flaws. Artifactory is widely used by development teams to manage software packages and build artifacts, meaning a compromise could expose sensitive source code, credentials, or supply chain components to attackers.
Organisations running JFrog Artifactory should treat this as an urgent priority. Given that administrative access can be obtained through authentication bypass, any delay in patching significantly increases the risk of unauthorised access to critical development infrastructure.