HomeVulnerabilitiesCritical JFrog Artifactory Flaw Under Active Attack Just Days After Patch Release

Critical JFrog Artifactory Flaw Under Active Attack Just Days After Patch Release

Security researchers have confirmed that a critical vulnerability in JFrog Artifactory, one of the most widely used platforms for storing and managing software packages, containers and other build artifacts, is being actively exploited in real attacks. The exploitation began within days of JFrog publishing patches for the flaw, giving many organizations little time to react.

The vulnerability, tracked as CVE-2026-82329, is an authentication bypass that allows an attacker with no valid credentials and no user interaction from a victim to gain full administrative control over a vulnerable Artifactory instance, as long as it is running under its default configuration. The flaw carries a CVSS score of 9.8 out of 10, reflecting how easy it is to exploit and how much damage a successful attack can cause. Because Artifactory often sits at the center of a company’s software build and deployment pipeline, an attacker with admin access could tamper with software packages before they reach production, potentially opening the door to a much larger supply chain compromise.

JFrog released patches on August 28, 2026, covering the affected version branches, and rolled the fix out to its cloud-hosted customers automatically. Self-hosted deployments, however, needed to be patched manually, and it is these instances that attackers appear to be targeting.

According to the exposure management firm watchTowr, which reported the in-the-wild exploitation, attackers have been observed “minting themselves admin tokens,” effectively handing themselves full control of affected systems without ever needing a username or password. Once an attacker holds an administrative token, they can create new accounts, read or modify stored packages, and pivot further into an organization’s development infrastructure.

JFrog has confirmed the nature of the bug, describing it as an authentication weakness that, “under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.” The company has not said how many organizations may have already been compromised.

The affected version branches are patched in Artifactory 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20. Organizations running self-hosted Artifactory instances that have not yet applied one of these updates should treat this as an urgent priority, since the exploitation window is already open. Restricting network access to the Artifactory management interface, where possible, can also reduce exposure while patching is completed.

Source: SecurityWeek, “Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild”

RELATED ARTICLES

1 COMMENT

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular