Cybersecurity Research

JFrog Artifactory Under Active Attack: Patch These Three Vulnerabilities Now

Wiz Research · 11 Sept 2026
Key Takeaway If your business uses JFrog Artifactory, check your version immediately, apply the latest security patches, and review logs for unexpected admin accounts or unfamiliar plugins.

Security researchers at Wiz have confirmed active, in-the-wild exploitation of three vulnerabilities affecting JFrog Artifactory, a widely used platform for managing software packages and code artifacts. Attackers are chaining CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 together to bypass authentication controls, escalate their privileges, and ultimately gain full administrative control of vulnerable instances.

Once inside, attackers have been observed creating persistent administrator accounts, deploying malicious code plugins to execute commands, and installing backdoors to maintain long-term access even after initial detection attempts. One of the flaws, CVE-2026-82329, is particularly serious because it allows an unauthenticated attacker with network access to obtain administrative privileges under Artifactory's default configuration, potentially exposing all artifacts, credentials, and connected integrations.

The scale of exposure is significant. According to Wiz's data, around two-thirds of organisations running Artifactory had at least one vulnerable instance at the time each flaw was disclosed: 67% for CVE-2026-42016, 69% for CVE-2026-42018, and 67% for CVE-2026-82329. Given that these vulnerabilities are being actively exploited rather than theoretical, organisations using Artifactory should treat patching as urgent.

Artifactory Vulnerability Active Exploitation

Summarised by CISO AI from Wiz Research. We link back to every original so you can read it yourself.