Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
ID: c56b6075-b12e-55ca-bf15-336941b82ca3
STIX ID: report--c56b6075-b12e-55ca-bf15-336941b82ca3
Feed Name: GBHackers
Active exploitation of three critical JFrog Artifactory vulnerabilities (CVE-2026-82329, CVE-2026-42018, CVE-2026-42016) enables unauthenticated or escalated administrative access; attackers have been observed obtaining admin-scoped tokens, creating persistent admin users, deploying malicious Groovy plugins, and installing Rust-based backdoors. The report lists affected and fixed versions, provides IoCs (IPs, payload URLs, file hash, account name patterns, C2 address), and urges urgent patching, network restrictions, and log review to mitigate supply-chain and repository compromise risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
