Threat actors are chaining multiple high-severity JFrog Artifactory vulnerabilities to bypass authentication, gain administrative privileges, and install persistent backdoors on self-hosted instances. Wiz says attackers have used CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329 for token theft, privilege escalation, code execution, and data exfiltration. #JFrogArtifactory #CVE-2026-42016 #CVE-2026-42018 #CVE-2026-82329 #Wiz
Keypoints
- Wiz reported active exploitation of three severe JFrog Artifactory flaws.
- CVE-2026-42018 can expose an anonymous-user token and sensitive repository data.
- CVE-2026-42016 enables privilege escalation through insufficient token validation.
- CVE-2026-82329 allows remote authentication bypass and admin access.
- Attackers used the flaws to deploy backdoors, malicious plugins, and persistent admin accounts.
Read More: https://www.securityweek.com/three-jfrog-artifactory-flaws-exploited-for-backdoor-deployment/