Close Menu
NCIJ Network NCIJ Network
    What's Hot

    I know why many east Germans vote AfD. And no, it’s not an inherited longing for dictatorship | Carolin Würfel

    September 15, 2026

    Australian politics live: Pauline Hanson offers qualified apologies to Albanese and Indigenous Australians over podcast comments | Australia news

    September 15, 2026

    ClickFix attacks are tricking Mac and Windows users into hacking themselves

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • I know why many east Germans vote AfD. And no, it’s not an inherited longing for dictatorship | Carolin Würfel
    • Australian politics live: Pauline Hanson offers qualified apologies to Albanese and Indigenous Australians over podcast comments | Australia news
    • ClickFix attacks are tricking Mac and Windows users into hacking themselves
    • Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
    • Coinbase-backed Base just exposed the uncomfortable truth about Ethereum’s L2s
    • Plague was killing entire families thousands of years before the Black Death
    • Roads, infrastructure prevent tigers from settling in Indian tiger reserve
    • Venezuela to join G20 energy meetings in Texas at US’s invitation
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 15
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 15, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors have been exploiting three high-severity vulnerabilities in JFrog Artifactory to compromise deployments and install backdoors, cybersecurity firm Wiz reports.

    Many organizations use Artifactory to manage software artifacts, binaries, AI models, containers, and packages.

    The three flaws, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, can allow attackers to bypass authentication and gain administrative privileges on vulnerable Artifactory instances.

    An improper authentication bug patched on August 12, CVE-2026-42018 can be exploited to obtain an anonymous-user token that provides access to sensitive artifacts and repository data. 

    Patched on July 27, CVE-2026-42016 is an insufficient token validation issue that can be exploited for privilege escalation.

    CVE-2026-82329 is an authentication bypass patched on August 28 that could be exploited remotely without authentication to gain administrative privileges. In-the-wild exploitation was reported a few days later.

    Advertisement. Scroll to continue reading.

    According to Wiz, CVE-2026-42018 and CVE-2026-42016 have been chained together since mid-August to obtain the anonymous-user token and then use it to elevate privileges to administrator.

    “Between August 15 and September 8, 2026, we observed multiple actors chain CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances,” Wiz says.

    The hackers were seen deploying persistent admin accounts, installing malicious plugins to gain arbitrary code execution, running shell commands through the plugin endpoint, dropping second-stage payloads, and occasionally updating the scripts for continuous access.

    Multiple threat actors also started exploiting CVE-2026-82329 in the first week of September, for configuration exfiltration, persistent admin access, token minting, cluster key exfiltration, and asset enumeration.

    In some instances, the attackers were seen attaching their own SSH keys to the user accounts they created.

    On Friday, CISA added CVE-2026-42018 and CVE-2026-42016 to its KEV catalog, one week after it added CVE-2026-82329 to the list. In line with BOD 26-04, federal agencies were given two weeks to patch their vulnerable instances.

    All organizations are advised to update their self-managed Artifactory deployments to versions 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, or 7.111.21 as soon as possible.

    Related: GitLab Vulnerability Exploited One Day After Disclosure

    Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

    Related: PaperCut Flaws Exploited in AI-Powered Attacks

    Related: Critical NetScaler Vulnerability Exploited in Attacks

    Artifactory Backdoor Deployment Exploited flaws JFrog
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Telus Warns Customers of Account Breaches

    The Race to Control AI and Protect What Makes Us Human

    Homebrew 7.0.0 gets built-in GUI, better security controls

    Personal, Financial Info Exposed in Revolut Data Breach

    Microsoft releases emergency Windows updates to fix RDS failures

    3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    I know why many east Germans vote AfD. And no, it’s not an inherited longing for dictatorship | Carolin Würfel

    September 15, 2026

    Australian politics live: Pauline Hanson offers qualified apologies to Albanese and Indigenous Australians over podcast comments | Australia news

    September 15, 2026

    ClickFix attacks are tricking Mac and Windows users into hacking themselves

    September 15, 2026

    Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

    September 15, 2026
    Latest Posts

    What Is an Air-Gapped Bitcoin Wallet? Why the Coldcard Exploit Changes the Conversation About Offline Security

    August 3, 2026

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    August 3, 2026

    T-Mobile will give you the new Samsung Galaxy Z Flip for practically nothing if you preorder now

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    I know why many east Germans vote AfD. And no, it’s not an inherited longing for dictatorship | Carolin Würfel

    September 15, 2026

    Australian politics live: Pauline Hanson offers qualified apologies to Albanese and Indigenous Australians over podcast comments | Australia news

    September 15, 2026

    ClickFix attacks are tricking Mac and Windows users into hacking themselves

    September 15, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.