Attackers are actively exploiting self-hosted JFrog Artifactory servers by chaining CVE-2026-42018, which exposes an internal anonymous-user token, with CVE-2026-42016, which fails to enforce token scope. The chain turns unauthenticated access into administrator authority. Attackers are also exploiting CVE-2026-82329, a CVSS 9.8 authentication-bypass flaw that independently grants administrative access under default configurations on affected release branches.
Observed post-compromise activity includes creation of persistent administrator accounts, deployment of malicious Groovy plugins for server-side code execution, webshell uploads, shell commands and downloaders, theft of credentials, configuration data and cluster join keys, and installation of a custom Rust-based backdoor with command-and-control capability. Organizations should immediately upgrade to JFrog's fixed builds, restrict internet exposure, and treat exposed vulnerable instances as potentially compromised by revoking tokens, rotating join keys, and reviewing administrator accounts, plugins, repositories, logs, and configuration changes.

See which actors are running it and whether you're in range.
16 events from the most recent confirmed update back to the earliest known activity.
CISA added the actively exploited JFrog Artifactory vulnerabilities CVE-2026-42016 and CVE-2026-42018 to its Known Exploited Vulnerabilities catalog. CISA set a September 25 remediation deadline for the vulnerabilities.
Wiz reported that 49% of organizations running Artifactory remained exposed to CVE-2026-82329 two weeks after the vulnerability's August 28 publication, down from 67% at publication.
CISA added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog. Fastly recorded approximately 406,000 exploitation attempts across its platform that day, though these did not represent confirmed compromises.
Actors exploiting CVE-2026-82329 exfiltrated Artifactory configuration data and cluster keys, minted tokens, enumerated assets, and created persistent administrator access. In some compromises, the attackers attached their own SSH keys to accounts they created.
A public exploit for the CVE-2026-82329 Artifactory authentication-bypass vulnerability appeared, followed by scanning activity. Threat actors also began separately exploiting the flaw to obtain administrator privileges on vulnerable default deployments.
Wiz reported that 67% of organizations running Artifactory had at least one instance vulnerable to CVE-2026-82329 at publication.
Multiple actors began exploiting self-hosted Artifactory servers by obtaining an anonymous-user token through CVE-2026-42018 and exchanging it for an administrator-scoped token through CVE-2026-42016. Observed compromises included persistent administrator accounts, malicious Groovy plugins, shell execution, payload downloads, and Rust backdoors with C2 capability.
CVE-2026-42018 was published as a high-severity improper-authentication flaw in JFrog Artifactory. The flaw could return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled; JFrog identified fixed versions across affected release branches.
Wiz reported that 69% of organizations running Artifactory had at least one instance vulnerable to CVE-2026-42018 at publication.
JFrog released a CVE-2026-42018 fix on the Artifactory 7.133 release branch.
CVE-2026-42016 was published as a high-severity improper-authorization vulnerability in self-hosted JFrog Artifactory. The flaw allows a low-privileged authenticated user to elevate privileges because token scope is not correctly validated; versions before 7.133.11 are affected.
JFrog released a fix for CVE-2026-42016, a high-severity token-scope validation flaw that could allow a low-privileged user to elevate privileges in Artifactory.
Wiz reported that 67% of organizations running Artifactory had at least one instance vulnerable to CVE-2026-42016 at the time of its publication.
JFrog released a fixed build for CVE-2026-42018 on the Artifactory 7.146 release branch.
CERT Polska reported that unknown actors exploited CVE-2026-67277 and CVE-2026-86060 to take control of vulnerable MikroTik RouterOS devices without authentication, naming the activity MikroTrick. CISA added both actively exploited RouterOS vulnerabilities to the KEV catalog.
Reported indicators for the Artifactory attacks included multiple command-and-control IP addresses, payload URLs, the SHA-1 hash of /tmp/.z, and suspicious persistent-account naming patterns such as 0xterror, svc_*, and Nxploited_*. The report also identified account names used by attackers, including jfrog-distribution, jfrog-insight, repo-service, backup-service, and ldap_admin.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
12 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcemkd-cirt.mk
Open sourceacn.gov.it
Open sourcethreataft.com
Open sourcethehackernews.com
Open sourcewiz.io
Open sourcecve.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.