Threat actors are chaining critical JFrog Artifactory vulnerabilities to bypass authentication, escalate to administrator access, and deploy a Rust-based backdoor on self-hosted servers. Wiz reported active exploitation across multiple environments, with attackers creating rogue accounts, stealing data, and maintaining persistence in minutes. #JFrogArtifactory #CVE202642018 #CVE202642016 #CVE202682329 #Wiz #watchTowr
Keypoints
- Attackers are exploiting JFrog Artifactory flaws to bypass authentication and gain admin access.
- Wiz confirmed an exploit chain using CVE-2026-42018 and CVE-2026-42016 across multiple environments.
- CVE-2026-82329 was also observed being used to mint administrator tokens.
- Threat actors installed malicious Groovy plugins and deployed a Rust backdoor for persistence.
- Defenders should patch immediately, inspect exposed instances, and review IoCs for suspicious activity.