Tech News
← Home  ·  All topics

Jfrog Artifactory

2 GoKawiil briefs on this topic

JFrog Artifactory bugs chained to plant Rust backdoor on self-hosted servers

Wiz researchers found multiple threat actors exploiting two Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, to escalate from a low-privileged anonymous session to full administrator access in under five minutes in some cases. Once inside, attackers installed malicious Groovy plugins to run commands and deployed a custom Rust-based backdoor with command-and-control capabilities, alongside webshells and stolen configuration data. A separate critical flaw, CVE-2026-82329, has also been used by other attackers to mint admin tokens on unpatched instances.

JFrog Artifactory bug lets attackers forge admin tokens in active exploits

A critical authentication bypass, CVE-2026-82329, in self-managed JFrog Artifactory deployments is being actively exploited to mint fraudulent administrator tokens without any prior authentication. The flaw sits in Artifactory's default configuration, and watchTowr researchers say attackers are already using it in the wild. JFrog patched the issue on August 28 across several version branches, and confirmed its cloud-hosted environments were never at risk.