• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

Three New JFrog Artifactory CVEs Actively Exploited in the Wild

Blog

CVE-2026-82329, CVE-2026-42018, and CVE-2026-42016, all affecting JFrog Artifactory, were added to CISA’s Known Actively Exploited (KEV) in September 2026 [1][2][3]. Artifactory acts as a central repository for software build artifacts, binaries, packages, containers, files, releases, and increasingly AI/ML artifacts. A compromise of Artifactory could allow an attacker to steal sensitive artifacts and credentials, tamper with or replace trusted packages and container images, and use the repository to distribute malicious code throughout downstream build and deployment pipelines. Numerous national CERT advisories have been issued for the actively exploited CVEs [1][2][3][4][5][6][7][8][9][10][11][12][13][14][15].

Banner illustration reading "Patch JFrog Artifactory Before It's Exploited"

Start Your Free Trial

Greenbone’s OPENVAS ENTERPRISE FEED includes regular detection of vulnerabilities that impact JFrog Artifactory, including new actively exploited ones [1][2][3]. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

Risk Assessment of Recent Attacks Targeting JFrog Artifactory

JFrog Artifactory first appeared in CISA’s KEV catalog in August 2026. The Greenbone blog covered the only other KEV CVE affecting JFrog Artifactory in the August Threat Report: The Vulnpocalypse Hits Full Force. The new attacks represent an increased focus on Artifactory and they are likely supported by AI-enabled exploit development.

On September 1st, watchTowr reported active exploitation of CVE-2026-82329, followed by Fastly on September 3rd. An attack campaign that chains CVE-2026-42018 and CVE-2026-42016 to target self-hosted instances was reported by Wiz Research. Combined, the attack trajectory for CVE-2026-42018 and CVE-2026-42016 allow a malicious, unauthenticated HTTP request to return an admin-scoped access token. Wiz also observed in-the-wild exploitation of CVE-2026-82329.

Several detailed technical analyses with proof-of-concept (PoC) exploit instructions are available online [1][2][3], and PoC exploit toolkits are available on GitHub [4][5], increasing the risk of additional attack campaigns.

Technical Summary of Actively Exploited JFrog Artifactory CVEs

The new actively exploited flaws are described below:

The three actively exploited JFrog Artifactory CVEs, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-82329
CVSS 9.8 · Critical EPSS 7.7% (94th)

An authentication weakness [CWE-287] allows an unauthenticated attacker with network access to obtain administrative privileges. The flaw is exploitable in the product’s default configuration. The flaw was disclosed on August 28th and the OPENVAS ENTERPRISE FEED added a remote banner check soon after the CVEs disclosure.

CVE-2026-42016
CVSS 8.8 · High EPSS 0.3% (18th)

An incorrect authorization vulnerability [CWE-863] allows privilege escalation. The root cause is a validation check that verifies a token’s signature and issuer, but not its scope. CVE-2026-42016 was published in late July 2026 and the OPENVAS ENTERPRISE FEED added a remote banner check soon after its disclosure.

CVE-2026-42018
CVSS 7.5 · High EPSS 0.3% (28th)

An improper authentication vulnerability [CWE-287] returns an anonymous-user token to an unauthenticated caller even if anonymous access is disabled. Exploitation can expose sensitive resources to an attacker. CVE-2026-42018 was published on August 12th, 2026 and the OPENVAS ENTERPRISE FEED added a remote banner check since its disclosure.

Mitigation for Actively Exploited JFrog Artifactory CVEs

Start Your Free Trial

Greenbone’s OPENVAS ENTERPRISE FEED includes regular detection of vulnerabilities that impact JFrog Artifactory, including new actively exploited ones [1][2][3]. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

The affected versions for each new actively exploited CVE are shown below:

CVE Affected Versions Fixed Version

CVE-2026-82329

7.161.0 before 7.161.20

7.146.0 before 7.146.38

7.133.0 before 7.133.29

7.125.0 before 7.125.20

7.117.0 before 7.117.28

7.111.4 before 7.111.21

7.161.20

7.146.38

7.133.29

7.125.20

7.117.28

7.111.21

CVE-2026-42018

< 7.111.20

7.117.0 before 7.117.27

7.125.0 before 7.125.19

7.133.0 before 7.133.28

7.146.0 before 7.146.8

7.111.20

7.117.27

7.125.19

7.133.28

7.146.8

CVE-2026-42016

< 7.133.11

7.133.11

JFrog only supports minor versions of self-managed Artifactory for 18 months after their release date. Self-managed minor versions 7.111.x are due to reach end of life (EOL) in October 2026. Full lists of fixed versions are available above and also in each OPENVAS SCAN detection result, and in the vendor’s security advisories. Users should carefully consider their exposure and upgrade to the latest 7.x version with an adequate support lifecycle.

If immediate upgrading is not possible, JFrog advises workaround mitigation of CVE-2026-82329 by configuring a strong, randomly generated additionalJoinKeys value under shared.security in the system.yaml file (or via JF_SHARED_SECURITY_ADDITIONALJOINKEYS for containerized/Helm deployments) and restarting the Access service to ensure that only trusted join keys are accepted for service registration. The vendor does not provide any workaround mitigations for CVE-2026-42018 or CVE-2026-42016.

Summary

Three JFrog Artifactory vulnerabilities have been added to CISA’s KEV catalog in September following confirmed active exploitation. The flaws create significant risk to software supply chains and downstream build environments. Public technical analyses and exploit tools further increase exposure. Organizations should identify affected Artifactory instances, upgrade to supported fixed releases, and apply JFrog’s documented workaround for CVE-2026-82329 where immediate patching is not possible.

Start Your Free Trial

Greenbone’s OPENVAS ENTERPRISE FEED includes regular detection of vulnerabilities that impact JFrog Artifactory, including new actively exploited ones [1][2][3]. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

 

Contact Test Now Buy Here Back to Overview
Joseph Lee
Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

15. September 2026/by Joseph Lee
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-09-15 15:01:532026-09-15 15:01:53Three New JFrog Artifactory CVEs Actively Exploited in the Wild

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: “MikroTrick” Exploit Chain Targets SSH-Exposed MikroTik RouterOS Devices Link to: “MikroTrick” Exploit Chain Targets SSH-Exposed MikroTik RouterOS Devices “MikroTrick” Exploit Chain Targets SSH-Exposed MikroTik RouterOS...
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn