logo

More JFrog Artifactory bugs under attack, and all 3 have patches

ID: 25fcf187-c201-514e-b325-6e28b8b57efa

STIX ID: report--25fcf187-c201-514e-b325-6e28b8b57efa

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-09-11

Date Updated: 2026-09-12

...
...

Multiple attackers are actively exploiting three recently patched JFrog Artifactory vulnerabilities to obtain administrative access to internet-exposed instances, install malicious Groovy plugins and a custom Rust backdoor, create persistent accounts and tokens, and exfiltrate configuration and keys; despite vendor patches, patch adoption has been slow and many organizations remain vulnerable, so immediate upgrading and network restrictions for internet-accessible Artifactory instances are strongly recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.