Hackers Chain Two JFrog Artifactory Flaws to Seize Admin Access and Deploy Backdoors
Attackers exploited two vulnerabilities in self-hosted JFrog Artifactory — CVE-2026-42018 and CVE-2026-42016 — chaining them to escalate an unauthenticated request into full administrator-level access, sometimes within five minutes. Security firm Wiz observed the attacks occurring between August 15 and September 8, 2026, across multiple compromised servers. Post-exploitation activity included creating persistent admin accounts, installing malicious Groovy plugins for code execution, and deploying a custom Rust backdoor with command-and-control capabilities. Because the administrator-scope token retains an anonymous username, all attacker actions appear in logs as 'token:anonymous', making detection by username searches ineffective. JFrog has released patched builds across multiple branches and advises affected users to upgrade immediately, rotate their cluster join key, and revoke any tokens issued since August 28; cloud-hosted instances are not affected.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in