CVE-2026-42016
Known exploited · CISA KEV
CVSS 8.1 HIGH: jFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a… EPSS 9% (95th percentile), up from 0.9%.
CISA federal remediation date Sep 25
Vulnerabilities & Exploits
Wiz says it has seen active exploitation of three JFrog Artifactory flaws, including authentication bypass and admin takeover, affecting self-hosted instances and making patching urgent. The vendor is directing admins to newer fixed builds, with CVE-2026-42016 calling for at least 7.133.11 and updates also covering CVE-2026-42018 and CVE-2026-82329.
One of the flaws accepts a token because its signature and issuer look valid but fails to check whether that token is allowed to do the requested action. That turns a valid-looking token into an admin pass, so an attacker who reaches the server can move from access to control.
For teams that use Artifactory as the source of builds or deployments, the exposure sits above a single server: repository content, stored secrets, and release artifacts can all become part of the foothold, and downstream systems may inherit trust in tampered packages.
1 source · Sep 17
Known exploited · CISA KEV
CVSS 8.1 HIGH: jFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a… EPSS 9% (95th percentile), up from 0.9%.
CISA federal remediation date Sep 25
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: jFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated… EPSS 8% (94th percentile).
CISA federal remediation date Sep 5 · date passed
Known exploited · CISA KEV
CVSS 7.5 HIGH: jFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is…
CISA federal remediation date Sep 25
Wiz Research
Building an AI Detection Engine for Agent Intent | Wiz Blog
Learn how Wiz is building a detection engine that understand AI agent reasoning to flag manipulated intent that legacy security tools miss.
originalPart of the PlainSec briefing for 2026-09-17
Every edition of this story: Wiz Finds Artifactory Admin Takeover in the Wild