Friday, 9 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

More JFrog Artifactory bugs under attack, and all 3 have patches

The Register ·
More JFrog Artifactory bugs under attack, and all 3 have patches

JFrog Artifactory instances continue to get hit hard.

Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over vulnerable instances - in some cases, just days after the vendor published a patch - and then using this illicit access to install malicious plugins and backdoors.

The three vulnerabilities are: CVE-2026-42018 is a high-severity, improper authentication flaw that can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled.

An attacker can use this token to authenticate to the repository manager and then access sensitive resources.

JFrog patched this vulnerability on August 12.

CVE-2026-42016 is a high-severity privilege-escalation bug.

Artifactory doesn’t properly validate the token’s scope, and this can allow an attacker with low-privileged access to elevate privileges and perform actions that they should not be allowed to do.

JFrog fixed this one on July 27.

CVE-2026-82329 is a critical authentication-bypass vulnerability that allows unauthenticated attackers with network access to obtain administrative privileges.

JFrog published a patch for it on August 28.

Earlier this month, security researchers told The Register that miscreants began battering internet-exposed systems vulnerable to CVE-2026-82329 just four days after JFrog disclosed the bug.

In addition to creating new administrative credentials, watchTowr’s honeypot network caught miscreants “enumerating users, groups, credential sets and federated access topologies,” said Yordan Ganchev, principal threat intelligence specialist at watchTowr.

The one thing everyone agrees upon is that attackers didn’t start exploiting any of these CVEs until after JFrog issued fixes.

In a Thursday report, Wiz security researchers “confirmed in-the-wild exploitation of all three vulnerabilities across multiple environments,” and noted that “patching velocity has been slow.” JFrog has not responded to any of The Register’s inquiries about attacks against any of the three CVEs. 'Patching velocity has been slow' Six weeks after JFrog disclosed CVE-2026-42016, 59 percent of organizations remain vulnerable, and 62 percent remain vulnerable to CVE-2026-42018 after four weeks.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›