Attackers are actively exploiting CVE-2026-82329, a critical authentication-bypass vulnerability in JFrog Artifactory, to mint administrative access tokens on exposed vulnerable instances. Under the default configuration, the flaw allows an unauthenticated network attacker to obtain administrative privileges and affects multiple Artifactory release branches.
JFrog released fixes on August 28; its cloud-hosted instances were already patched, but self-hosted customers must upgrade to a fixed Artifactory release immediately. WatchTowr reported exploitation within days of disclosure. The vulnerability was not yet listed in CISA's Known Exploited Vulnerabilities catalog, and is distinct from the previously patched Artifactory flaws connected to the OpenAI-Hugging Face testing-environment escape incident.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
CISA added the actively exploited JFrog Artifactory authentication-bypass vulnerability CVE-2026-82329 to its Known Exploited Vulnerabilities catalog. The KEV entry set a September 5, 2026 remediation deadline for U.S. federal civilian agencies.
In some observed CVE-2026-82329 intrusions, attackers created backdoor Artifactory users after gaining administrative access, allowing them to retain persistence. The activity accompanied administrator-token generation and reconnaissance of compromised environments.
Observed exploitation of CVE-2026-82329 included not only minting administrator tokens but also enumerating Artifactory users, groups, credential sets, and federated access topologies. The activity followed exploitation of self-managed vulnerable instances.
watchTowr reported observing attackers actively exploiting CVE-2026-82329 against vulnerable Artifactory instances. The attackers were reportedly minting Artifactory administrative tokens.
JFrog published advisories and released updates for CVE-2026-82329, a critical Artifactory authentication-bypass flaw that can grant an unauthenticated network attacker administrative privileges under the default configuration. JFrog had already deployed the fixes to its cloud-hosted instances and advised self-hosted customers to upgrade to patched releases.
CISA added the separate JFrog Artifactory vulnerability CVE-2026-66384 to its Known Exploited Vulnerabilities catalog. The flaw requires authentication and can allow writes outside the intended Docker cache path under specific conditions.
Reporting noted that administrative tokens forged through CVE-2026-82329 before remediation may remain valid after an Artifactory binary update, as those credentials use separate expiration controls. This creates a persistence risk that may require invalidating or reviewing forged tokens in addition to applying patches.
A CVEReports report described alleged weaknesses in JFrog Access cryptographic initialization, cluster joining-key validation, and JWT signature verification that could permit reconstruction of master.key, forging of administrative tokens, or acceptance of crafted inter-node messages. The report characterized the self-managed Artifactory issue as network-reachable and critical (CVSS 9.8).
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
17 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcesocradar.io
Open sourcecysecurity.news
Open sourceheise.de
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcegithub.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.