Artifactory flaws chained in attacks deploying backdoor malware

Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are chaining critical JFrog Artifactory vulnerabilities to bypass authentication, escalate to administrator access, and deploy a Rust-based backdoor on self-hosted servers. Wiz reported active exploitation across multiple environments, with attackers creating rogue accounts, stealing data, and maintaining persistence in minutes. #JFrogArtifactory #CVE202642018 #CVE202642016 #CVE202682329 #Wiz #watchTowr

Keypoints

  • Attackers are exploiting JFrog Artifactory flaws to bypass authentication and gain admin access.
  • Wiz confirmed an exploit chain using CVE-2026-42018 and CVE-2026-42016 across multiple environments.
  • CVE-2026-82329 was also observed being used to mint administrator tokens.
  • Threat actors installed malicious Groovy plugins and deployed a Rust backdoor for persistence.
  • Defenders should patch immediately, inspect exposed instances, and review IoCs for suspicious activity.

Read More: https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/