Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: jfrog-artifactory (1 article)Clear

Attackers exploit a critical JFrog Artifactory flaw to mint admin tokens

Days after disclosure, attackers are exploiting a critical authentication-bypass flaw in JFrog Artifactory, the widely used repository manager for binaries, packages, containers, and build artifacts. Tracked as CVE-2026-82329 and scored 9.8, the flaw lets an unauthenticated attacker with network access gain administrative privileges under Artifactory's default configuration. Researchers at watchTowr observed exploitation beginning September 1, with attackers minting admin tokens for themselves and enumerating users, groups, and credentials. Because Artifactory sits at the center of software supply chains and CI/CD pipelines, admin access lets attackers tamper with build pipelines, poison trusted dependencies, and push malicious code downstream to customers. JFrog patched it in version 7.161.20 on August 28.

Check
Patch self-managed JFrog Artifactory to 7.161.20 or later immediately, prioritizing internet-exposed instances, then inspect audit logs for unexpected admin tokens, user enumeration, and any changes to hosted artifacts.
Affected
Organizations running self-managed JFrog Artifactory in default configuration (CVE-2026-82329); an unauthenticated attacker with network access can gain admin, mint tokens, harvest credentials, and tamper with the supply chain, and exploitation is active.
Fix
Patch now, rotate Artifactory credentials and tokens, review hosted packages and build pipelines for tampering, restrict network exposure of the service, and treat any exposed unpatched instance as a supply-chain compromise.