Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
ID: 9b648619-7109-50e8-b44c-2085497d4b99
STIX ID: report--9b648619-7109-50e8-b44c-2085497d4b99
Feed Name: The Hacker News
Attackers exploited chained Artifactory vulnerabilities (CVE-2026-42018 and CVE-2026-42016) and a separate critical authentication bypass (CVE-2026-82329) to obtain administrator privileges on self-hosted JFrog Artifactory instances between mid‑August and early September; they created admin accounts, installed malicious Groovy plugins, dropped binaries including a Rust backdoor with C2 capabilities, and exfiltrated cluster join keys. JFrog published fixed builds for affected branches and Fastly/Wiz recommend treating exposed servers as compromised, rotating join keys, revoking tokens minted since late August, and auditing administrator accounts, repositories, and configuration changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
