Exploit
JFrog Artifactory vulnerabilities actively exploited for rapid admin access
Key Facts
Signal Type
Exploit
Industry
Cybersecurity
Companies
JFrog, Wiz
Date
September 28, 2026
Three vulnerabilities in self-hosted JFrog Artifactory—CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329—are being actively exploited by attackers to gain administrator access in under five minutes. The flaws allow authentication bypass and privilege escalation, and can be chained to create persistent admin accounts, steal credentials, and execute arbitrary code.
Security firm Wiz reported that the attack method involves sending unauthenticated HTTP requests to exploit these vulnerabilities. CISA has added the vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to confirmed active exploitation.
Organizations running self-hosted JFrog Artifactory instances, particularly those with exposed management interfaces, are at risk. JFrog has urged these organizations to assume compromise and investigate for signs of exploitation.
Patching the vulnerabilities is necessary to close the entry points, but it does not remove any existing intruders. Affected organizations must also hunt for persistent admin accounts and other indicators of compromise.
This active exploitation creates urgent demand for security services, including incident response, threat hunting, and vulnerability management. Security teams will need to prioritize patching and forensic investigation.
Organizations should monitor for signs of exploitation, including unexpected admin accounts, unusual HTTP requests, and unauthorized code execution. The presence of these indicators may require immediate containment and eradication.
Since patching does not remove existing intruders, affected organizations must assume compromise and conduct a thorough investigation. Security teams should also track CVE-2026-42016 and related CVEs in their threat feeds for new reporting or exploitation activity.
Source:
ThreatCluster Threat FeedGet cybersecurity signals in your CRM
Data breaches, ransomware events, funding rounds, and M&A across security vendors and targets.
