JFrog Artifactory Auth Bypass CVE-2026-82329 Exploited Within Days of Disclosure
A critical authentication bypass vulnerability (CVE-2026-82329, CVSS 9.8) in self-hosted JFrog Artifactory was patched on August 28, 2026, with fixes available across three maintenance branches. By September 1, threat intelligence firm watchTowr detected active exploitation in honeypot environments, where attackers were creating administrator tokens and mapping access credentials. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 2, giving federal agencies until September 5 to remediate. The vulnerability affected default installations rather than misconfigured ones, as an empty join key was part of the shipped software, broadening the at-risk population significantly. Security experts warn that patching alone is insufficient, since attackers may have already established persistent access through malicious plugins or rogue tokens that survive an upgrade.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in