According to watchTowr, threat actors are taking advantage of a recently fixed critical security vulnerability affecting JFrog Artifactory just days after it was made public.
The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), an instance of an Artifactory authentication bypass that may grant administrative access.
According to a description of the defect on CVE.org, JFrog Artifactory has an authentication vulnerability that, under normal settings, may enable an unauthenticated attacker with network access to achieve administrative rights.
On August 28, 2026, JFrog published Artifactory version 7.161.20, which fixed the vulnerability. The following versions are impacted:
- 7.161.0 > 7.161.19
- 7.146.0 > 7.146.36
- 7.133.0 > 7.133.28
- 7.125.0 > 7.125.19
- 7.117.0 > 7.117.27
- 7.111.4 > 7.111.21
In a LinkedIn article, Vercel CEO Guillermo Rauch stated that it impacts default configurations, doesn’t require authentication, and doesn’t require user engagement. Because Artifactory hosts binaries, you can essentially poison everything, making it an RCE bomb read more about Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
