logo

Critical JFrog Artifactory Authentication Bypass Exploited in the Wild

ID: 0f2ebca2-4cc2-5a33-b497-db54864ae099

STIX ID: report--0f2ebca2-4cc2-5a33-b497-db54864ae099

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-09-01

Date Updated: 2026-09-11

Author: Divya

...
...

Security researchers warn that a critical authentication-bypass vulnerability (CVE-2026-82329) in JFrog Artifactory enables attackers to create administrator access tokens, and watchTowr reported exploitation in the wild as of September 1. The report highlights the high risk to CI/CD pipelines and software supply chains—attackers with admin tokens can exfiltrate or modify artifacts, upload backdoored packages, alter permissions, and establish persistence—and advises organizations to patch, verify exposed instances, and review authentication activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.