CVE Tools
Back to feed
Exploited in the wild JFrog Artifactory rce JFrog auth-bypass

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Wiz has confirmed active exploitation of a vulnerability chain in self-hosted JFrog Artifactory servers that allows attackers to gain administrator control. By combining an unauthenticated token disclosure flaw (CVE-2026-42018) with a privilege escalation bug (CVE-2026-42016), threat actors can swap anonymous tokens for administrative scope to deploy malicious plugins and establish command-and-control channels. This attack campaign occurred between August 15 and September 8, targeting systems that had not yet applied fixes released by JFrog.

Administrators should urgently verify their deployment status against JFrog's security advisories, as patching alone does not remove previously created attacker accounts or revoked tokens. While the chained flaws require specific version combinations, a separate critical authentication bypass (CVE-2026-82329, CVSS 9.8) was also exploited independently during this period, affecting up to version 7.161.20. Organizations must rotate join keys, audit unauthorized administrator accounts, and ensure all instances are updated to the latest fixed releases.