Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump Can’t Lower Gas Pump Prices Via Venezuelan Oil

    September 1, 2026

    Lawsuit alleging rape aboard Navy vessel was dismissed and classified as worker’s comp issue, documents show

    September 1, 2026

    Israeli Authorities Charge 12 Guards in Beating Death of Palestinian Prisoner

    September 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump Can’t Lower Gas Pump Prices Via Venezuelan Oil
    • Lawsuit alleging rape aboard Navy vessel was dismissed and classified as worker’s comp issue, documents show
    • Israeli Authorities Charge 12 Guards in Beating Death of Palestinian Prisoner
    • Map Apps Are Handling Trump’s Renaming of Lake Ontario to Lake America Differently
    • Ed Miliband promises ‘comprehensive reset’ of UK policy toward Israel | Foreign policy
    • US defends Venezuela deal as Chevron prepares to expand operations
    • The Diamond Moon and Other Astronomical Events to See in September 2026
    • Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 1, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 01, 2026Vulnerability / Supply Chain Attack

    Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr.

    The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory.

    “JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges,” according to a description of the flaw on CVE.org.

    The vulnerability was patched by JFrog with Artifactory version 7.161.20 released on August 28, 2026. It affects the following versions –

    • 7.161.0 > 7.161.19
    • 7.146.0 > 7.146.36
    • 7.133.0 > 7.133.28
    • 7.125.0 > 7.125.19
    • 7.117.0 > 7.117.27
    • 7.111.4 > 7.111.21

    “It affects default configs, requires no auth, no user interaction,” Vercel CEO Guillermo Rauch said in a post on LinkedIn. “It’s an RCE bomb because Artifactory hosts binaries, so you can basically poison everything, but an admin escalation can cause damage even beyond that.”

    Cybersecurity

    The issue resides in JFrog Access, which is designed to issue and validate credentials. “Instances without an additional join key configured receive a ‘phantom’ join key that attackers can abuse to forge access and mint administrator-level credentials,” Yordan Ganchev, principal threat intelligence specialist at watchTowr, said in a statement shared with The Hacker News.

    Ganchev also pointed out that threat actors have begun to weaponize the flaw as of September 1, 2026, to generate admin tokens and enumerate users, groups, credential sets and federated access topologies.

    “This moved from disclosure to real-world exploitation with uncomfortable efficiency,” Ganchev added. “Anyone following along knows what comes next: things will get worse.”

    “When attackers gain admin level access to a central software supply chain system, they can do what every engineering team does best – build, ship and distribute software fast. From there, they could tamper with build pipelines, move laterally into production systems and potentially push malicious changes downstream to customers.”

    Organizations that are running self-managed versions of JFrog Artifactory are recommended to apply patches to internet-exposed systems with immediate effect, as well as inspect audit logs, rotate exposed credentials, and review connected systems for malicious changes or backdoor access.

    Admin Artifactory Attackers critical days Disclosure exploit Flaw JFrog Mint tokens
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Palo Alto Networks Acquires AI Agent Platform Console

    Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense

    Critical Langflow flaw exploited to steal OpenAI and AWS keys

    13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

    Novocure data breach affects more than 1,400 cancer patients

    Hackers push malicious Virtualizor update in BGP hijacking attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump Can’t Lower Gas Pump Prices Via Venezuelan Oil

    September 1, 2026

    Lawsuit alleging rape aboard Navy vessel was dismissed and classified as worker’s comp issue, documents show

    September 1, 2026

    Israeli Authorities Charge 12 Guards in Beating Death of Palestinian Prisoner

    September 1, 2026

    Map Apps Are Handling Trump’s Renaming of Lake Ontario to Lake America Differently

    September 1, 2026
    Latest Posts

    Bitcoin Only Makes Up 1% Of Legendary Investor Ray Dalio’s Portfolio

    July 30, 2026

    AI Harnesses Burst With Potential Exploit Opps

    July 30, 2026

    LinkedIn actually adds a ‘seems like AI slop’ button

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump Can’t Lower Gas Pump Prices Via Venezuelan Oil

    September 1, 2026

    Lawsuit alleging rape aboard Navy vessel was dismissed and classified as worker’s comp issue, documents show

    September 1, 2026

    Israeli Authorities Charge 12 Guards in Beating Death of Palestinian Prisoner

    September 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.