Threat actors are exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory, just days after JFrog released a patch in version 7.161.20. The flaw affects default configurations and can let unauthenticated attackers gain administrative access, enabling token theft, user enumeration, and potential supply chain compromise. #JFrogArtifactory #CVE2026-82329 #JFrogAccess
Keypoints
- CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory.
- JFrog patched the flaw in Artifactory version 7.161.20 on August 28, 2026.
- The issue affects several 7.x release ranges and works in default configurations without authentication.
- Attackers are already weaponizing the bug to mint admin tokens and enumerate users, groups, and credentials.
- Organizations should patch exposed systems, inspect logs, rotate credentials, and check for malicious changes.
Read More: https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html