[REVISION HISTORY]
JFrog Artifactory security vulnerabilities
Updated 1 time since CLSTR started tracking revisions of this situation.
What changed
2026-09-12 12:18 UTC → 2026-09-13 09:08 UTC ·
added
removed
Security authorities and researchers have identified and tracked multiple critical vulnerabilities within the JFrog Artifactory platform. On September 2, the General Directorate of Information Systems Security (DGSSI) issued alerts regarding a critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory, noting it was already being actively exploited. The DGSSI also issued an important alert regarding vulnerabilities in Mozilla Firefox versions prior to 155. Subsequent reports confirmed that attackers are actively exploiting three specific flaws in JFrog Artifactory to gain administrative control, install malicious plugins, and create backdoors. These include the critical CVE-2026-82329 authentication-bypass flaw, as well as high-severity improper authentication (CVE-2026-42018) and privilege-escalation (CVE-2026-42016) bugs. Evidence suggests exploitation often begins shortly after patches are released, with some attacks targeting systems just four days after disclosure. On September 11, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added several of these flaws to its Known Exploited Vulnerabilities (KEV) catalog. CISA noted that attackers are reportedly chaining multiple vulnerabilities, specifically CVE-2026-42016 and CVE-2026-42018, to achieve administrative privilege escalation. This process allows for unauthorized access and the creation of administrative accounts used to install backdoors and malicious plugins.
Versions
- 2026-09-13 09:08 UTC JFrog Artifactory security vulnerabilities
- 2026-09-12 12:18 UTC JFrog Artifactory security vulnerabilities
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.