Attackers Took Admin Control of JFrog Artifactory Servers, Wiz Reports

Attackers have been chaining vulnerabilities in JFrog Artifactory to take administrative control of self-hosted servers, and in several cases have left a backdoor behind, the cloud security company Wiz said in a report published Sept. 10, 2026.
Artifactory is repository software that organizations use to hold the packages, build artifacts and credentials their own software is assembled from. Administrative control of an instance reaches the whole deployment and everything it manages, Wiz Research said.
Wiz said that between Aug. 15 and Sept. 8 multiple actors combined two of the flaws, CVE-2026-42018 and CVE-2026-42016, against self-hosted instances. Neither one grants administrative control by itself, according to the company; used in sequence, they do.
On the compromised servers, Wiz said, it found administrator accounts set up to survive a restart, commands run on the machine itself, and in multiple cases a custom backdoor written in Rust that could take instructions from a remote operator. A third flaw, CVE-2026-82329, which, Wiz said, gets past authentication in Artifactory's default setup, was exploited separately.
The US Cybersecurity and Infrastructure Security Agency added the two chained flaws to its catalog of known exploited vulnerabilities on Sept. 11, saying the additions were based on evidence of active exploitation. A CISA directive requires federal civilian agencies to prioritize repairs to listed flaws, and the agency says it encourages every other organization to do the same.
Wiz also published patching figures drawn from its own data. It said 67% of organizations running Artifactory had at least one vulnerable instance on July 27, when the first of the two chained flaws was made public, and that 59% were still vulnerable six weeks later. Those percentages cover the organizations Wiz can see with its own products, not the industry as a whole.
Wiz said fixed releases are available for each affected version branch, and advised organizations to restrict network access to instances reachable from the internet while they upgrade.
