CVE Tools
Back to feed
Exploited in the wild JFrog Artifactory auth-bypass JFrog privilege-escalation

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Cybersecurity researchers at Wiz report active exploitation of three high-severity vulnerabilities in JFrog Artifactory, enabling threat actors to deploy backdoors and seize administrative control. The affected issues, identified as CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, facilitate authentication bypasses and privilege escalation on self-hosted instances.

Attackers have been chaining these bugs since mid-August to inject persistent administrator accounts, install malicious plugins for arbitrary code execution, and exfiltrate sensitive cluster data. CISA has added all three CVEs to its Known Exploited Vulnerabilities catalog, mandating urgent remediation for federal agencies. Organizations should immediately update their deployments to versions 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, or 7.111.21.