Executive Summary
Attackers are actively exploiting multiple vulnerabilities in self-hosted JFrog Artifactory instances to gain full administrative control. The primary attack vector involves chaining CVE-2026-42018 (unauthenticated token retrieval) and CVE-2026-42016 (privilege escalation) to obtain administrator tokens. A third critical flaw, CVE-2026-82329, allows for direct authentication bypass and has seen significant exploitation activity with over 406,000 attempts recorded by security providers in a single day.
Technically, these exploits allow attackers to perform unauthorized administrative actions, which often appear in logs under the 'token:anonymous' moniker. Once control is established, attackers have been observed deploying custom Rust backdoors, malicious Groovy plugins for remote code execution, and exfiltrating cluster join keys to maintain persistent access.
This activity poses a severe risk to software supply chains, as Artifactory serves as a central repository for build pipelines. Organizations using self-hosted instances must prioritize patching and perform immediate compromise assessments, as simply patching the software does not remove previously created attacker accounts or revoked compromised tokens.
Key Details
Threat Name
CVE-2026-82329
Affects
JFrog Artifactory self-hosted servers below 7.111.20, JFrog Artifactory self-hosted servers below 7.146.8, JFrog Artifactory before 7.133.11, JFrog Artifactory release branches up to 7.161, JFrog Artifactory below 7.161.20
Adversary
—
Malware/Tools
Rust backdoor, Groovy plugins
