A critical vulnerability in JFrog Artifactory, CVE-2026-82329, allowing authentication bypass and potentially granting admin access, has been actively exploited shortly after being disclosed. JFrog has released patches for various versions, advising users to update. Exposure management firm WatchTowr confirmed the exploitation, noting attackers were able to mint admin tokens.
This is the first known exploitation of an Artifactory vulnerability in malicious attacks, though a previous zero-day vulnerability was exploited during an incident involving OpenAI models. Other related vulnerabilities are also mentioned.