EXPLOITED

Artifactory under attack. Wiz saw the admin chain and Rust backdoors.

Self-hosted JFrog Artifactory: actors chain CVE-2026-42018 + CVE-2026-42016 to admin scope in under five minutes, then plant Groovy plugins and a Rust C2 backdoor. CVE-2026-82329 (CVSS 9.8) is also in play. Wiz: 49–62% of reachable instances still vulnerable to at least one of the three. Victim tally: Undisclosed.

Sep 11, 2026 · 3 min read

Wiz Research (blog dated Sep 10; changelog Sep 11) confirms in-the-wild exploitation of three Artifactory flaws on self-hosted instances. Between Aug 15 and Sep 8, multiple actors chained CVE-2026-42018 (anonymous JWT handed to an unauthenticated caller even with anonymous access off) with CVE-2026-42016 (token scope not enforced) to mint an admin-scoped token. In some cases: first request to persistent admin account in under five minutes. Logs can show token:anonymous doing admin work.

Post-exploit: persistent admin accounts, malicious Groovy plugins for code execution, droppers into /tmp / /dev/shm, and a custom Rust backdoor with C2. Separately, CVE-2026-82329 (CVSS 9.8 auth bypass on default config; already on CISA KEV) was exploited Sep 1–8 — join-key theft, config exfil, long-lived tokens. Wiz cloud telemetry: at publication ~67% of orgs with Artifactory had a vulnerable instance; as of the report 49–62% of reachable instances remain vulnerable to at least one of the three. SaaS/cloud Artifactory: vendor says no action; self-hosted must patch.

Fixed builds (branch): 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20 or later. Patching does not revoke minted tokens or remove planted admins — hunt rogue accounts, plugins, and rotate join keys / tokens. Primary: Wiz. Secondary: BleepingComputer / The Hacker News amplification Sep 11.

Sources