Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 8 sources · 9 days · First seen · Last updated
JFrog Artifactory security vulnerabilities
Overview
Security authorities and researchers have identified and tracked multiple critical vulnerabilities within the JFrog Artifactory platform.
On September 2, the General Directorate of Information Systems Security (DGSSI) issued alerts regarding a critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory, noting it was already being actively exploited. The DGSSI also issued an important alert regarding vulnerabilities in Mozilla Firefox versions prior to 155.
Subsequent reports confirmed that attackers are actively exploiting three specific flaws in JFrog Artifactory to gain administrative control, install malicious plugins, and create backdoors. These include the critical CVE-2026-82329 authentication-bypass flaw, as well as high-severity improper authentication (CVE-2026-42018) and privilege-escalation (CVE-2026-42016) bugs. Evidence suggests exploitation often begins shortly after patches are released, with some attacks targeting systems just four days after disclosure.
On September 11, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added several of these flaws to its Known Exploited Vulnerabilities (KEV) catalog. CISA noted that attackers are reportedly chaining multiple vulnerabilities, specifically CVE-2026-42016 and CVE-2026-42018, to achieve administrative privilege escalation. This process allows for unauthorized access and the creation of administrative accounts used to install backdoors and malicious plugins.
Entities
JFrog Artifactory · MikroTik RouterOS · WatchTowr · OpenAI · CISA
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 6 SOURCES] CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory that can return an internal anonymous-user token to an unauthenticated caller. cybernoz.com · cybersecurity-news.de · www.it-boltwise.de · sempreupdate.com.br · www.theregister.com · +1 more
- [● 4 SOURCES] CVE-2026-42016 is an incorrect authorization vulnerability in JFrog Artifactory that can lead to privilege escalation. cybernoz.com · cybersecurity-news.de · www.it-boltwise.de · thehackernews.com
- [● 3 SOURCES] CISA added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. cybernoz.com · www.it-boltwise.de · thehackernews.com
- [● 2 SOURCES] CVE-2026-84869 is an improper privilege management vulnerability in ConnectWise ScreenConnect with a CVSS score of 9.9. cybernoz.com · thehackernews.com
- [● 2 SOURCES] CVE-2026-67277 is a missing authentication vulnerability in MikroTik RouterOS that can allow kernel memory disclosure. cybernoz.com · thehackernews.com
- [● 2 SOURCES] CVE-2026-86060 is a command vulnerability in MikroTik RouterOS that can allow privilege escalation. cybernoz.com · thehackernews.com
- [○ 1 SOURCE] Wiz security researchers confirmed in-the-wild exploitation of three JFrog Artifactory vulnerabilities across multiple environments. www.theregister.com
- [○ 1 SOURCE] Attackers using CVE-2026-82329 were observed enumerating users, groups, and credential sets. www.theregister.com
Timeline
-
3 days ago
[TECHNOLOGY] 6 sourcesCISA adds five exploited flaws in Artifactory, ScreenConnect, and RouterOS to KEV catalogCISA has added five actively exploited vulnerabilities in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its KEV catalog, following reports of administrative privilege escalation and un-
-
12 days ago
[TECHNOLOGY] 2 sourcesDGSSI issues security alerts for JFrog Artifactory and Mozilla FirefoxThe DGSSI has issued critical and important security alerts for JFrog Artifactory and Mozilla Firefox, noting active exploitation of certain vulnerabilities.
Sources
cert.ssi.gouv.fr · cybernoz.com · cybersecurity-news.de · it-boltwise.de · lebrief.ma · sempreupdate.com.br · thehackernews.com · theregister.co.uk
This summary has been updated 1 time: see revision history