Three New JFrog Artifactory CVEs Actively Exploited in the Wild
CVE-2026-82329, CVE-2026-42018, and CVE-2026-42016, all affecting JFrog Artifactory, were added to CISA’s Known Actively Exploited (KEV) in September 2026 [1][2][3]. Artifactory acts as a central repository for software build artifacts, binaries, packages, containers, files, releases, and increasingly AI/ML artifacts. A compromise of Artifactory could allow an attacker to steal sensitive artifacts and credentials, tamper with or replace trusted packages and container images, and use the repository to distribute malicious code throughout downstream build and deployment pipelines. Numerous national CERT advisories have been issued for the actively exploited CVEs [1][2][3][4][5][6][7][8][9][10][11][12][13][14][15].

Start Your Free Trial
Greenbone’s OPENVAS ENTERPRISE FEED includes regular detection of vulnerabilities that impact JFrog Artifactory, including new actively exploited ones [1][2][3]. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.
Risk Assessment of Recent Attacks Targeting JFrog Artifactory
JFrog Artifactory first appeared in CISA’s KEV catalog in August 2026. The Greenbone blog covered the only other KEV CVE affecting JFrog Artifactory in the August Threat Report: The Vulnpocalypse Hits Full Force. The new attacks represent an increased focus on Artifactory and they are likely supported by AI-enabled exploit development.
On September 1st, watchTowr reported active exploitation of CVE-2026-82329, followed by Fastly on September 3rd. An attack campaign that chains CVE-2026-42018 and CVE-2026-42016 to target self-hosted instances was reported by Wiz Research. Combined, the attack trajectory for CVE-2026-42018 and CVE-2026-42016 allow a malicious, unauthenticated HTTP request to return an admin-scoped access token. Wiz also observed in-the-wild exploitation of CVE-2026-82329.
Several detailed technical analyses with proof-of-concept (PoC) exploit instructions are available online [1][2][3], and PoC exploit toolkits are available on GitHub [4][5], increasing the risk of additional attack campaigns.
Technical Summary of Actively Exploited JFrog Artifactory CVEs
The new actively exploited flaws are described below:
The three actively exploited JFrog Artifactory CVEs, each shown with its CVSS severity band and EPSS exploitation-probability score
An authentication weakness [CWE-287] allows an unauthenticated attacker with network access to obtain administrative privileges. The flaw is exploitable in the product’s default configuration. The flaw was disclosed on August 28th and the OPENVAS ENTERPRISE FEED added a remote banner check soon after the CVEs disclosure.
An incorrect authorization vulnerability [CWE-863] allows privilege escalation. The root cause is a validation check that verifies a token’s signature and issuer, but not its scope. CVE-2026-42016 was published in late July 2026 and the OPENVAS ENTERPRISE FEED added a remote banner check soon after its disclosure.
An improper authentication vulnerability [CWE-287] returns an anonymous-user token to an unauthenticated caller even if anonymous access is disabled. Exploitation can expose sensitive resources to an attacker. CVE-2026-42018 was published on August 12th, 2026 and the OPENVAS ENTERPRISE FEED added a remote banner check since its disclosure.
Mitigation for Actively Exploited JFrog Artifactory CVEs
Start Your Free Trial
Greenbone’s OPENVAS ENTERPRISE FEED includes regular detection of vulnerabilities that impact JFrog Artifactory, including new actively exploited ones [1][2][3]. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.
The affected versions for each new actively exploited CVE are shown below:
JFrog only supports minor versions of self-managed Artifactory for 18 months after their release date. Self-managed minor versions 7.111.x are due to reach end of life (EOL) in October 2026. Full lists of fixed versions are available above and also in each OPENVAS SCAN detection result, and in the vendor’s security advisories. Users should carefully consider their exposure and upgrade to the latest 7.x version with an adequate support lifecycle.
If immediate upgrading is not possible, JFrog advises workaround mitigation of CVE-2026-82329 by configuring a strong, randomly generated additionalJoinKeys value under shared.security in the system.yaml file (or via JF_SHARED_SECURITY_ADDITIONALJOINKEYS for containerized/Helm deployments) and restarting the Access service to ensure that only trusted join keys are accepted for service registration. The vendor does not provide any workaround mitigations for CVE-2026-42018 or CVE-2026-42016.
Summary
Three JFrog Artifactory vulnerabilities have been added to CISA’s KEV catalog in September following confirmed active exploitation. The flaws create significant risk to software supply chains and downstream build environments. Public technical analyses and exploit tools further increase exposure. Organizations should identify affected Artifactory instances, upgrade to supported fixed releases, and apply JFrog’s documented workaround for CVE-2026-82329 where immediate patching is not possible.
Start Your Free Trial
Greenbone’s OPENVAS ENTERPRISE FEED includes regular detection of vulnerabilities that impact JFrog Artifactory, including new actively exploited ones [1][2][3]. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.
Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.
He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.
Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.



