JFrog Artifactory custom Rust backdoor deployment
Malware Activity
Summary
Hide ▲
Show ▼
A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after intruders obtained administrative access, making the compromise more durable and harder to evict. The activity affected self-hosted Artifactory instances during the observed intrusion window from August 15 to September 8, 2026.
Related Happenings
JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)
Vulnerability
H score42
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
How related:
Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token.
About this happening:
JFrog Artifactory self-hosted servers were actively exploited through CVE-2026-42018 and CVE-2026-42016, letting attackers bypass authentication, steal JWTs, and e...
JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)
VulnerabilityHow related: Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token.
About this happening: JFrog Artifactory self-hosted servers were actively exploited through CVE-2026-42018 and CVE-2026-42016, letting attackers bypass authentication, steal JWTs, and e...
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation Wave
H score42
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
How related:
Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token.
About this happening:
Multiple threat actors are actively exploiting JFrog Artifactory through CVE-2026-42018 and CVE-2026-42016 to bypass authentication, mint admin-scoped tokens, and depl...
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation WaveHow related: Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token.
About this happening: Multiple threat actors are actively exploiting JFrog Artifactory through CVE-2026-42018 and CVE-2026-42016 to bypass authentication, mint admin-scoped tokens, and depl...
JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
Vulnerability
H score56
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under def...
JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
VulnerabilityAbout this happening: CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under def...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
H score55
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation WaveAbout this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
Artifactory token-refresh via legacy credential endpoint security flaw
Vulnerability
H score44
First: 27.08.2026 21:36
Last: 27.08.2026 21:36
Sources 1
About this happening:
Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeo...
Artifactory token-refresh via legacy credential endpoint security flaw
VulnerabilityAbout this happening: Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeo...
Timeline
-
11.09.2026 19:29 2 articles · 2h ago
Rust backdoor deployed on self-hosted JFrog Artifactory servers
Initial DisclosureWiz reported multiple threat actors chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory instances to bypass authentication, mint admin-scoped tokens, create administrator accounts in under five minutes, install malicious Groovy plugins, and deploy a custom Rust backdoor with C2 capabilities; the same report also notes CVE-2026-82329 being used to mint administrator tokens and recommends upgrading to fixed Artifactory releases and investigating exposed instances for suspicious token creation, rogue administrator accounts, plugin activity, and enumeration requests.
Show sources
- Artifactory flaws chained in attacks deploying backdoor malware — www.bleepingcomputer.com — 11.09.2026 19:29
- Artifactory flaws chained in attacks deploying backdoor malware — www.bleepingcomputer.com — 11.09.2026 19:29