Critical JFrog Artifactory Authentication Bypass Exploited in the Wild
ID: 0f2ebca2-4cc2-5a33-b497-db54864ae099
STIX ID: report--0f2ebca2-4cc2-5a33-b497-db54864ae099
Feed Name: GBHackers
Security researchers warn that a critical authentication-bypass vulnerability (CVE-2026-82329) in JFrog Artifactory enables attackers to create administrator access tokens, and watchTowr reported exploitation in the wild as of September 1. The report highlights the high risk to CI/CD pipelines and software supply chains—attackers with admin tokens can exfiltrate or modify artifacts, upload backdoored packages, alter permissions, and establish persistence—and advises organizations to patch, verify exposed instances, and review authentication activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
