Skip to content
See the World Through ScienceA project of ALLATRA

Attackers Took Admin Control of JFrog Artifactory Servers, Wiz Reports

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Close-up of rack-mounted servers, with a tape library unit above and a 1U server with lit status indicators below.
Rack-mounted servers in a server room. The reported attacks targeted self-hosted JFrog Artifactory instances, which organizations run on their own machines. Illustrative photo, not equipment involved in the reported activity."Server Room" by cobaltfish, via flickr, CC-BY-SA-2.0 · CC-BY-SA-2.0

Attackers have been chaining vulnerabilities in JFrog Artifactory to take administrative control of self-hosted servers, and in several cases have left a backdoor behind, the cloud security company Wiz said in a report published Sept. 10, 2026.

Artifactory is repository software that organizations use to hold the packages, build artifacts and credentials their own software is assembled from. Administrative control of an instance reaches the whole deployment and everything it manages, Wiz Research said.

Wiz said that between Aug. 15 and Sept. 8 multiple actors combined two of the flaws, CVE-2026-42018 and CVE-2026-42016, against self-hosted instances. Neither one grants administrative control by itself, according to the company; used in sequence, they do.

On the compromised servers, Wiz said, it found administrator accounts set up to survive a restart, commands run on the machine itself, and in multiple cases a custom backdoor written in Rust that could take instructions from a remote operator. A third flaw, CVE-2026-82329, which, Wiz said, gets past authentication in Artifactory's default setup, was exploited separately.

The US Cybersecurity and Infrastructure Security Agency added the two chained flaws to its catalog of known exploited vulnerabilities on Sept. 11, saying the additions were based on evidence of active exploitation. A CISA directive requires federal civilian agencies to prioritize repairs to listed flaws, and the agency says it encourages every other organization to do the same.

Wiz also published patching figures drawn from its own data. It said 67% of organizations running Artifactory had at least one vulnerable instance on July 27, when the first of the two chained flaws was made public, and that 59% were still vulnerable six weeks later. Those percentages cover the organizations Wiz can see with its own products, not the industry as a whole.

Wiz said fixed releases are available for each affected version branch, and advised organizations to restrict network access to instances reachable from the internet while they upgrade.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Attackers Took Admin Control of JFrog Artifactory Servers, Wiz Reports

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.