JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administrative access. The abuse began days after public disclosure and is focused on internet-exposed instances. Attackers are already using the flaw to mint admin tokens and enumerate users, groups, credential sets and federated access topologies. The rapid post-patch weaponization raises the risk of downstream tampering in software supply chain environments.
Related Happenings
JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
Vulnerability
H score56
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
How related:
"JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges," according to a description of the flaw on CVE.org.
About this happening:
CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under def...
JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
VulnerabilityHow related: "JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges," according to a description of the flaw on CVE.org.
About this happening: CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under def...
PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)
Vulnerability
H score51
First: 28.08.2026 20:12
Last: 28.08.2026 20:12
Sources 1
About this happening:
PaperCut NG and PaperCut MF are facing active exploitation of two newly patched flaws, allowing attackers to bypass authentication and reach remote code executio...
PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)
VulnerabilityAbout this happening: PaperCut NG and PaperCut MF are facing active exploitation of two newly patched flaws, allowing attackers to bypass authentication and reach remote code executio...
Artifactory token-refresh via legacy credential endpoint security flaw
Vulnerability
H score44
First: 27.08.2026 21:36
Last: 27.08.2026 21:36
Sources 1
About this happening:
Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeo...
Artifactory token-refresh via legacy credential endpoint security flaw
VulnerabilityAbout this happening: Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeo...
PaperCut customer confirmed compromise incidents
Incident
H score41
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
About this happening:
PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
PaperCut customer confirmed compromise incidents
IncidentAbout this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
Latest development: 01.09.2026 10:48
Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF print management servers to hijack the external user-lookup function and dump DB tables via Derby, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th).
PaperCut emergency patches for public-facing NG/MF servers
Security Patch Release
H score51
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
About this happening:
PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the prin...
PaperCut emergency patches for public-facing NG/MF servers
Security Patch ReleaseAbout this happening: PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the prin...
Latest development: 01.09.2026 10:48
Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against vulnerable PaperCut NG/MF print management servers to steal data, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th) and reporting an auth bypass used to hijack PaperCut's external user-lookup and dump DB tables via Derby.
Timeline
-
01.09.2026 20:53 1 articles · 3h ago
JFrog releases Artifactory 7.161.20 to fix CVE-2026-82329
Mitigation Patch UpdateJFrog released Artifactory 7.161.20 on August 28, 2026 to patch CVE-2026-82329, an authentication bypass in JFrog Artifactory that could let an unauthenticated attacker with network access obtain administrative privileges under default configuration.
Show sources
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — thehackernews.com — 01.09.2026 20:53
-
01.09.2026 20:53 2 articles · 3h ago
Threat actors weaponize CVE-2026-82329 to mint admin tokens in JFrog Artifactory
Exploitation ObservedAs of September 1, 2026, threat actors had begun weaponizing CVE-2026-82329 against JFrog Artifactory, using the authentication bypass to generate admin tokens and enumerate users, groups, credential sets and federated access topologies.
Show sources
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — thehackernews.com — 01.09.2026 20:53
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — thehackernews.com — 01.09.2026 20:53