JFrog Artifactory Flaws Actively Exploited, Enabling Full Supply-Chain Compromise
JFrog disclosed and patched three authentication and authorization vulnerabilities in self-hosted Artifactory in September 2026, with CVSS scores ranging from 7.5 to 9.8. The most critical flaw, CVE-2026-82329, allows attackers to forge a cluster join token via an empty default join key and escalate to platform administrator. Security vendors reported that attackers were chaining these flaws to create persistent admin accounts, install malicious plugins, and export credentials and repository configuration. Because Artifactory acts as a central credential store for CI/CD pipelines, a compromised instance can expose every downstream build system that trusts it, including cached packages. CISA added the vulnerabilities to its Known Exploited Vulnerabilities catalog on September 12, 2026, setting a federal remediation deadline of September 25, with JFrog recommending upgrades to fixed versions 7.161.20 or 7.133.11 depending on the branch.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in