www.securityweek.com 14 Sept 2026, 09:27 UTC

Hackers Exploit JFrog Artifactory Bugs to Install Persistent Backdoors

Hackers Exploit JFrog Artifactory Bugs to Install Persistent Backdoors

THREAT actors have been exploiting three high-severity vulnerabilities in self-hosted JFrog Artifactory deployments to obtain administrative access and install backdoors, according to cybersecurity firm Wiz. Artifactory is widely used to manage software artefacts, binaries, AI models, containers and packages.

The flaws are CVE-2026-42018, an improper authentication issue patched on 12 August; CVE-2026-42016, an insufficient token-validation flaw patched on 27 July; and CVE-2026-82329, a remotely exploitable authentication bypass patched on 28 August.

Wiz observed multiple attackers chaining CVE-2026-42018 and CVE-2026-42016 between 15 August and 8 September 2026. The chain obtains an anonymous-user token before escalating privileges to administrator. Attackers then created persistent administrator accounts, installed malicious plugins capable of arbitrary code execution, ran shell commands through the plugin endpoint and deployed additional payloads. Some also attached their own SSH keys to newly created accounts.

Multiple actors began exploiting CVE-2026-82329 during the first week of September to exfiltrate configuration and cluster keys, mint tokens, enumerate assets and maintain administrative access. CISA added CVE-2026-82329 to its Known Exploited Vulnerabilities catalogue before adding the other two flaws on 11 September. Organisations using self-managed Artifactory are advised to update to version 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28 or 7.111.21.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline