JFrog Artifactory users are facing a serious security problem after attackers were observed exploiting a newly disclosed critical vulnerability in the platform. The flaw is tracked as CVE-2026-82329 and carries a CVSS score of 9.8, making it a critical-level issue. JFrog says the vulnerability is an authentication weakness that, under the default configuration, can allow an unauthenticated attacker with network access to obtain administrative privileges. The vulnerability affects self-managed Artifactory installations, while JFrog Cloud environments have already been protected.
The worrying part is that the vulnerability is not only theoretical anymore. Security researchers from watchTowr reported seeing attackers actively abusing vulnerable, internet-exposed Artifactory systems shortly after the flaw became public. According to the observations, attackers were able to mint administrator tokens for themselves, giving them powerful access to the affected Artifactory environment. The activity was seen through watchTowr’s Attacker Eye honeypot, showing that threat actors were already looking for vulnerable installations instead of simply waiting for organizations to patch them.
Once an attacker obtains administrator-level access, the possible damage becomes much more serious because Artifactory is commonly used to store and distribute software packages, binaries, containers, AI models and other files used by development and deployment systems. Reported attacker activity included checking users, groups, credential sets and federated access information. Administrative access can also allow sensitive security settings to be changed, artifacts to be read and existing packages to potentially be poisoned or replaced. This creates a major concern for organizations that automatically trust and pull software from their Artifactory repositories.
Security experts are particularly concerned about the possible software supply-chain impact. Artifactory repositories are often connected to build and deployment pipelines, meaning software stored there may automatically move into other systems. If an attacker manages to replace a trusted package or binary with a malicious version, downstream systems could potentially receive and execute that altered software. Black Duck’s Collin Hogue-Spears warned that administrative access can reach released artifacts that downstream systems already trust and pull automatically. This means the risk can extend beyond the Artifactory server itself.
JFrog publicly disclosed and patched CVE-2026-82329 on August 28, 2026. The company released fixes for several affected Artifactory branches, including versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20. Organizations running self-hosted Artifactory are advised to move to the appropriate fixed release as quickly as possible. JFrog has also stated that affected cloud environments were already fortified, meaning customers using those protected cloud instances do not need to take action for this specific vulnerability.
At this stage, the full scale of the attacks is still not known. Researchers have confirmed exploitation attempts and the creation of administrator tokens, but there is no clear public information showing how many organizations were successfully compromised. Details such as confirmed victims, complete attack telemetry and indicators of compromise remain limited. For companies running self-managed Artifactory, the key step is therefore to check the installed version, apply the appropriate security update and investigate unusual administrative activity or unexpected changes to repositories.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news