Multiple threat actors have been chaining three JFrog Artifactory vulnerabilities, CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, in active exploitation confirmed between August 15 and September 8, using two of the bugs together to extract an anonymous-user token and escalate it to admin privileges, or exploiting the third for unauthenticated remote privilege elevation on its own. Once inside, attackers deployed persistent admin accounts, malicious plugins enabling arbitrary code execution, and SSH keys attached to newly created user accounts for sustained access. Patches are available across six version branches, and CISA has given federal agencies a two-week mandatory patch window.
Adrian Culley, Offensive Security Engineer, SafeBreach:
“Two medium-severity bugs beat a critical one here, and that’s the story. CVE-2026-42018 leaks an internal anonymous-user token; CVE-2026-42016 fails to enforce that token’s scope. Neither is exploitable alone — chained, they turn an unauthenticated request into an admin-scoped token, matching T1190 and T1078, before attackers reach Artifactory’s native plugin framework for code execution.
What makes this a validation failure rather than a patching one: both CVEs were fixed in July and August, yet the majority of exposed organisations were still running vulnerable versions when the chaining campaign started in mid-August. Patch availability was never the gap — verifying the token boundary actually held was.
Owning the fix isn’t the same as knowing whether your environment would have caught the chain before the plugin endpoint was reached. That’s a control you test, not one you assume.
Priority: upgrade to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20+; audit for unexpected admin accounts and attached SSH keys; review plugin installs and token-issuance logs; then validate the auth-bypass-to-RCE chain directly rather than relying on patch status as a proxy.”
It’s time to patch all the things when it comes to JFrog. Because clearly this has gotten out to the public domain which means that it’s only a matter of time before you get pwned.
Attackers are chaining three JFrog Artifactory bugs to plant admin backdoors
Posted in Commentary with tags JFrog on September 14, 2026 by itnerdMultiple threat actors have been chaining three JFrog Artifactory vulnerabilities, CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, in active exploitation confirmed between August 15 and September 8, using two of the bugs together to extract an anonymous-user token and escalate it to admin privileges, or exploiting the third for unauthenticated remote privilege elevation on its own. Once inside, attackers deployed persistent admin accounts, malicious plugins enabling arbitrary code execution, and SSH keys attached to newly created user accounts for sustained access. Patches are available across six version branches, and CISA has given federal agencies a two-week mandatory patch window.
Adrian Culley, Offensive Security Engineer, SafeBreach:
“Two medium-severity bugs beat a critical one here, and that’s the story. CVE-2026-42018 leaks an internal anonymous-user token; CVE-2026-42016 fails to enforce that token’s scope. Neither is exploitable alone — chained, they turn an unauthenticated request into an admin-scoped token, matching T1190 and T1078, before attackers reach Artifactory’s native plugin framework for code execution.
What makes this a validation failure rather than a patching one: both CVEs were fixed in July and August, yet the majority of exposed organisations were still running vulnerable versions when the chaining campaign started in mid-August. Patch availability was never the gap — verifying the token boundary actually held was.
Owning the fix isn’t the same as knowing whether your environment would have caught the chain before the plugin endpoint was reached. That’s a control you test, not one you assume.
Priority: upgrade to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20+; audit for unexpected admin accounts and attached SSH keys; review plugin installs and token-issuance logs; then validate the auth-bypass-to-RCE chain directly rather than relying on patch status as a proxy.”
It’s time to patch all the things when it comes to JFrog. Because clearly this has gotten out to the public domain which means that it’s only a matter of time before you get pwned.
Leave a comment »