JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Multiple threat actors are actively exploiting JFrog Artifactory through CVE-2026-42018 and CVE-2026-42016 to bypass authentication, mint admin-scoped tokens, and deploy a Rust-based backdoor on vulnerable self-hosted servers. The exploitation wave ran between August 15 and September 8, 2026, with some compromises reaching administrator creation in under five minutes. Wiz says the activity spans multiple environments and affects a substantial share of reachable instances. Related activity also includes CVE-2026-82329 being used to mint administrator tokens.
Related Happenings
JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)
Vulnerability
H score42
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
How related:
Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token.
About this happening:
JFrog Artifactory self-hosted servers were actively exploited through CVE-2026-42018 and CVE-2026-42016, letting attackers bypass authentication, steal JWTs, and e...
JFrog Artifactory authentication bypass and token validation flaws (multiple vulnerabilities)
VulnerabilityHow related: Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token.
About this happening: JFrog Artifactory self-hosted servers were actively exploited through CVE-2026-42018 and CVE-2026-42016, letting attackers bypass authentication, steal JWTs, and e...
JFrog Artifactory custom Rust backdoor deployment
Malware Activity
H score34
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
How related:
“Across multiple cases, we observed a custom Rust backdoor with C2 capabilities being dropped.”
About this happening:
A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after...
JFrog Artifactory custom Rust backdoor deployment
Malware ActivityHow related: “Across multiple cases, we observed a custom Rust backdoor with C2 capabilities being dropped.”
About this happening: A custom Rust backdoor was dropped on compromised JFrog Artifactory servers, giving attackers C2-enabled remote control and persistence. The malware was deployed after...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
H score53
First: 05.09.2026 10:31
Last: 05.09.2026 10:31
Sources 1
About this happening:
PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation WaveAbout this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
Vulnerability
H score56
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under def...
JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)
VulnerabilityAbout this happening: CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under def...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
H score55
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation WaveAbout this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
Timeline
-
11.09.2026 19:29 2 articles · 2h ago
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Initial DisclosureBetween August 15 and September 8, 2026, attackers used CVE-2026-42018 and CVE-2026-42016 to move from low-privilege access to administrator control on self-hosted Artifactory systems. Early activity already showed rapid token abuse and account creation across multiple environments.
Show sources
- Artifactory flaws chained in attacks deploying backdoor malware — www.bleepingcomputer.com — 11.09.2026 19:29
- Artifactory flaws chained in attacks deploying backdoor malware — www.bleepingcomputer.com — 11.09.2026 19:29