CVE Tools
Back to feed
Exploited in the wild JFrog Artifactory auth-bypass JFrog supply-chain

Attackers Pounce on Critical Artifactory Flaw Following Disclosure

Dark Reading·By Jai Vijayan··4 min read
CVE Tools coverage

Threat actors have begun active exploitation of CVE-2026-82329, a critical authentication bypass vulnerability in JFrog Artifactory, just days after its public disclosure. With a CVSS score of 9.8, this flaw enables unauthenticated attackers to gain administrative privileges on self-hosted deployments, potentially compromising software repositories and build artifacts. While JFrog clarified that this incident is distinct from recent attacks involving OpenAI and Hugging Face, watchTowr telemetry confirms attackers are already minting admin tokens and enumerating system details. Organizations using affected versions must urgently patch their systems and rotate credentials, as Internet-exposed instances should be treated as compromised.