# JFrog Artifactory security vulnerabilities

> Live situation record from CLSTR: https://clstr.news/situations/jfrog-artifactory-security-vulnerabilities
> Updated: 2026-09-11T11:16:00.000Z. Sources: 8. Developments: 2.

Security authorities and researchers have identified and tracked multiple critical vulnerabilities within the JFrog Artifactory platform.

On September 2, the General Directorate of Information Systems Security (DGSSI) issued alerts regarding a critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory, noting it was already being actively exploited. The DGSSI also issued an important alert regarding vulnerabilities in Mozilla Firefox versions prior to 155.

Subsequent reports confirmed that attackers are actively exploiting three specific flaws in JFrog Artifactory to gain administrative control, install malicious plugins, and create backdoors. These include the critical CVE-2026-82329 authentication-bypass flaw, as well as high-severity improper authentication (CVE-2026-42018) and privilege-escalation (CVE-2026-42016) bugs. Evidence suggests exploitation often begins shortly after patches are released, with some attacks targeting systems just four days after disclosure.

On September 11, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added several of these flaws to its Known Exploited Vulnerabilities (KEV) catalog. CISA noted that attackers are reportedly chaining multiple vulnerabilities, specifically CVE-2026-42016 and CVE-2026-42018, to achieve administrative privilege escalation. This process allows for unauthorized access and the creation of administrative accounts used to install backdoors and malicious plugins.

## Claims

- CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory that can return an internal anonymous-user token to an unauthenticated caller. (corroborated by 6 sources)
- CVE-2026-42016 is an incorrect authorization vulnerability in JFrog Artifactory that can lead to privilege escalation. (corroborated by 4 sources)
- CISA added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. (corroborated by 3 sources)
- CVE-2026-84869 is an improper privilege management vulnerability in ConnectWise ScreenConnect with a CVSS score of 9.9. (corroborated by 2 sources)
- CVE-2026-67277 is a missing authentication vulnerability in MikroTik RouterOS that can allow kernel memory disclosure. (corroborated by 2 sources)
- CVE-2026-86060 is a command vulnerability in MikroTik RouterOS that can allow privilege escalation. (corroborated by 2 sources)
- Wiz security researchers confirmed in-the-wild exploitation of three JFrog Artifactory vulnerabilities across multiple environments. (single source)
- Attackers using CVE-2026-82329 were observed enumerating users, groups, and credential sets. (single source)

## Timeline

### 2026-09-11: CISA adds five exploited flaws in Artifactory, ScreenConnect, and RouterOS to KEV catalog

CISA has added five actively exploited vulnerabilities in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its KEV catalog, following reports of administrative privilege escalation and un-

6 sources. https://clstr.news/cluster/jfrog-artifactory-vulnerabilities-exploited-in-the-wild

### 2026-09-02: DGSSI issues security alerts for JFrog Artifactory and Mozilla Firefox

The DGSSI has issued critical and important security alerts for JFrog Artifactory and Mozilla Firefox, noting active exploitation of certain vulnerabilities.

2 sources. https://clstr.news/cluster/dgssi-issues-security-alerts-for-jfrog-artifactory-and-mozilla-firefox

---
Cite as: JFrog Artifactory security vulnerabilities. CLSTR, https://clstr.news/situations/jfrog-artifactory-security-vulnerabilities
