A 9.8 in JFrog Artifactory Went From Patch to Real Attacks in Four Days

CVE-2026-82329 (CVSS 9.8) gives an unauthenticated attacker admin access to JFrog Artifactory. Exploited four days after the patch.

Get Advisory Support
Critical CVE-2026-82329

JFrog Artifactory is the shelf that software teams keep their finished software on. Build a package, sign it, store it there, and every server and laptop downstream pulls from that shelf. CVE-2026-82329, rated CVSS 9.8, is an authentication bypass in JFrog Access, the component responsible for issuing and validating credentials. The CVE record states that under a default configuration, an unauthenticated attacker with network access may obtain administrative privileges. According to watchTowr, instances that were never given an additional join key receive what the firm calls a "phantom" join key, and an attacker who knows this can forge access and mint administrator-level credentials without a password and without any user clicking anything. JFrog fixed the flaw in Artifactory 7.161.20, released on August 28, 2026; the affected self-managed ranges are 7.161.0 through 7.161.19, 7.146.0 through 7.146.36, 7.133.0 through 7.133.28, 7.125.0 through 7.125.19, 7.117.0 through 7.117.27, and 7.111.4 through 7.111.21. Yordan Ganchev of watchTowr told The Hacker News that threat actors began weaponizing the flaw on September 1, 2026, generating admin tokens and enumerating users, groups, credential sets, and federated access topologies — that is, mapping who trusts whom before deciding what to do next. Four days from a quiet release note to hands-on-keyboard activity is the part worth sitting with.

Recommended action: If your organization runs self-managed Artifactory, patch to 7.161.20 today, starting with anything reachable from the internet. Then assume the patch is only the first step: pull the audit logs and look for token creation and user enumeration you cannot account for, rotate any credential the platform held or issued, and review connected systems — build pipelines, deployment targets, cloud accounts — for changes nobody on your team made. Most healthcare providers and municipalities in Puerto Rico do not run Artifactory themselves, and that is exactly why this belongs in a bulletin rather than in a developer chat. Your electronic health record vendor, your billing clearinghouse, your practice management platform, and your managed service provider almost certainly do run something like it, and an attacker with administrator access to a build repository can tamper with the software that later gets installed in your environment. This is the practical shape of third-party risk. Send a short note to your critical software and IT vendors this week asking three questions: do you use JFrog Artifactory or a comparable artifact repository, was it patched for CVE-2026-82329, and did you find evidence of unauthorized access. Keep the answers in writing with your vendor file — under 45 CFR §164.308(b) your business associate arrangements are supposed to give you a basis for relying on those vendors, and a dated response is the kind of documentation an auditor or a cyber insurer will ask to see. If a vendor cannot answer within a few days, that silence is itself a finding worth recording in your risk register.
Sources: CVE record for CVE-2026-82329 on CVE.org, JFrog self-managed release notes and security advisories, watchTowr statements attributed to Yordan Ganchev, The Hacker News (September 1, 2026).

← All security bulletins

Bulletins summarize publicly reported information for awareness and are not a substitute for vendor advisories or a tailored assessment.

Worried about a bulletin above?

We can assess your exposure to the threats above and other active campaigns, and help you remediate quickly.

Request an Exposure Check