Millions of DevOps and Database Platforms Found Exposed on Public Internet
A ZoomEye internet scan conducted on September 19, 2026, identified millions of internal development and data platforms publicly accessible online, including over 1.3 million GitLab instances and 680,000 MongoDB deployments. The review was prompted by a critical authentication bypass vulnerability in JFrog Artifactory (CVE-2026-82329, CVSS 9.8), confirmed as actively exploited, which affects default configurations and requires no prior perimeter breach. Although only 1,526 Artifactory instances were detected, security researchers warn that even a small exposed population is sufficient for targeted attackers. The findings highlight a recurring pattern where internal tools are placed on the internet for convenience, inadvertently creating significant security risks. Experts recommend keeping such platforms off the public internet, patching known vulnerabilities promptly, enforcing authentication, and rotating credentials whenever exposure is detected.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in