CISA KEV Alert 11 Sept 2026, 20:33 UTC

CISA Warns of Exploited JFrog Artifactory Authentication Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-42018 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects JFrog Artifactory and is named the JFrog Artifactory Improper Authentication Vulnerability. It can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

The flaw is an improper authentication vulnerability that can be exploited remotely without authentication. An attacker may obtain an internal token and use it to access sensitive resources. The vulnerability carries a CVSS score of 7.5, rated High. The available data does not confirm whether a patch is available.

CISA’s KEV listing confirms active exploitation. The supplied data does not identify known ransomware campaign use. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 25 September 2026.

CISA requires organisations to apply mitigations in accordance with JFrog’s instructions, while following CISA’s BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. Agencies should apply the applicable BOD 26-04 guidance for cloud services or discontinue use of Artifactory if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and comply with BOD 26-04 patching guidance. Although the deadline applies directly to FCEB agencies, all organisations using Artifactory should review their exposure and take appropriate action.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline