logo

Artifactory flaws chained in attacks deploying backdoor malware

ID: 35f91ae6-aea0-5cef-a032-e673793e9123

STIX ID: report--35f91ae6-aea0-5cef-a032-e673793e9123

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Bill Toulas

...
...

Threat actors are chaining critical JFrog Artifactory vulnerabilities (CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329) to bypass authentication, escalate to admin, create accounts and long-lived tokens, install malicious Groovy plugins, and deploy a Rust-based backdoor; Wiz observed active exploitation across multiple self-hosted instances between 2026-08-15 and 2026-09-08, with recommended immediate upgrades to specified Artifactory releases and investigation of exposed instances and suspicious tokens, accounts, plugins, and enumeration activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.