Vulnerabilities & Exploits

Wiz Finds Artifactory Admin Takeover in the Wild

Wiz says it has seen active exploitation of three JFrog Artifactory flaws, including authentication bypass and admin takeover, affecting self-hosted instances and making patching urgent. The vendor is directing admins to newer fixed builds, with CVE-2026-42016 calling for at least 7.133.11 and updates also covering CVE-2026-42018 and CVE-2026-82329.

One of the flaws accepts a token because its signature and issuer look valid but fails to check whether that token is allowed to do the requested action. That turns a valid-looking token into an admin pass, so an attacker who reaches the server can move from access to control.

For teams that use Artifactory as the source of builds or deployments, the exposure sits above a single server: repository content, stored secrets, and release artifacts can all become part of the foothold, and downstream systems may inherit trust in tampered packages.

1 source · Sep 17

CVE-2026-42016

NVD KEV

Known exploited · CISA KEV

CVSS 8.1 HIGH: jFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a… EPSS 9% (95th percentile), up from 0.9%.

CISA federal remediation date Sep 25

CVE-2026-82329

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: jFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated… EPSS 8% (94th percentile).

CISA federal remediation date Sep 5 · date passed

CVE-2026-42018

NVD KEV

Known exploited · CISA KEV

CVSS 7.5 HIGH: jFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is…

CISA federal remediation date Sep 25

Timeline

Sources

Part of the PlainSec briefing for 2026-09-17

Every edition of this story: Wiz Finds Artifactory Admin Takeover in the Wild

More from today