JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
Is CVE-2026-82329 exploited?
Listed in the CISA KEV catalog on 2026-09-02.
Federal remediation due 2026-09-05.
Past that date by 18 days.
EPSS puts exploitation in the next 30 days at 8%.
Public exploit code: none found in monitored sources.