logo

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

ID: 0b111d6f-5c5b-58cf-aa91-081a485d20f6

STIX ID: report--0b111d6f-5c5b-58cf-aa91-081a485d20f6

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-09-02

Date Updated: 2026-09-10

Author: Bill Toulas

...
...

A critical authentication-bypass vulnerability (CVE-2026-82329) in self-managed JFrog Artifactory is being exploited in the wild to forge administrative tokens, allowing unauthenticated attackers with network access to gain admin privileges and potentially replace trusted artifacts in downstream systems; JFrog released patched versions, cloud instances were reportedly protected, but victim counts and IoCs remain unclear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.