Exploited Vulnerabilities in JFrog Artifactory Lead to Backdoor Installation
Attackers exploited two patched vulnerabilities in self-hosted JFrog Artifactory between mid-August and early September 2026 to gain administrator access. The U.S. cybersecurity agency CISA added these flaws to its Known Exploited Vulnerabilities catalog on September 11, 2026. This chained attack allowed the creation of admin accounts and the installation of malicious plugins as a backdoor. The vulnerabilities, which had patches available for over a month, affected specific software versions and were rated as High severity.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in