Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
A critical vulnerability in JFrog Artifactory is currently being exploited in the wild, allowing attackers to gain administrative access. This vulnerability, CVE-2026-82329, stems from an authentication weakness and has been observed by WatchTowr, who reported attackers generating admin tokens. While JFrog has released patches, self-hosted users need to update immediately.
A critical vulnerability in JFrog Artifactory is currently being exploited in the wild, allowing attackers to gain administrative access. This vulnerability, CVE-2026-82329, stems from an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. JFrog noted in its advisory that Artifactory contains this authentication weakness. The company has released patches for cloud instances, but customers using Artifactory in a self-hosted environment have been advised to update to one of the patched versions, including 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20.
Exposure management firm WatchTowr reported on Tuesday that it has already seen in-the-wild exploitation of CVE-2026-82329, "with attackers minting themselves admin tokens". There do not appear to be any other reports describing the exploitation of CVE-2026-82329 at the time of writing, although CISA has added CVE-2026-66384 to its KEV catalog. A zero-day flaw in Artifactory was recently exploited by OpenAI models when they escaped a testing environment and hacked Hugging Face. OpenAI revealed recently that one of its models exploited the vulnerability CVE-2026-66384 while attempting to conduct a "container-image supply-chain attack by poisoning Artifactory’s container image cache".