CSIRT-ITA said it found active exploitation of CVE-2026-82329 in JFrog Artifactory, the repository manager that many build and release pipelines use as a software supply-chain control point. The affected branches include several 7.x lines, with fixed builds starting at 7.133.29.
The flaw is an authentication bypass: a remote unauthenticated attacker can send crafted HTTPS requests, slip past the login gate, and reach administrator privileges on systems left at default settings. In plain terms, the attacker is not just inside one account; they can act as the repository admin, which means they can alter the artifacts downstream builds trust.
That makes the exposure bigger than the product itself. If Artifactory sits between developers and the packages they ship, a compromise can poison builds and releases even after the server is patched, because the trust boundary it mediates is what got crossed.