Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
Threat actors are actively exploiting multiple vulnerabilities in JFrog Artifactory to deploy backdoors and install persistent administrative accounts. Wiz reported a campaign involving chaining CVE-2026-42018 and CVE-2026-42016 to gain elevated privileges and install malicious plugins, leading to remote code execution and data exfiltration. CISA has added the vulnerabilities to its KEV catalog, urging agencies to patch immediately.
Threat actors are leveraging multiple vulnerabilities within JFrog Artifactory to establish persistent access and deploy malicious payloads. JFrog Artifactory is a widely used tool for managing software artifacts, and its vulnerabilities have been actively exploited. According to Wiz, a campaign began in mid-August, chaining CVE-2026-42018 and CVE-2026-42016 to obtain an anonymous-user token, which then allowed attackers to escalate privileges and install malicious plugins. These plugins were used to run shell commands, drop second-stage payloads, and update scripts for continuous access.
Starting in the first week of September, CVE-2026-82329 was exploited to exfiltrate configurations, obtain persistent admin access, mint tokens, and enumerate assets. Attackers were observed attaching their own SSH keys to newly created user accounts. CISA added CVE-2026-42018 and CVE-2026-42016 to its KEV catalog on August 31st, following a two-week period mandated by BOD 26-04 for federal agencies to patch their vulnerable instances.
Organizations are advised to update their self-managed Artifactory deployments to versions 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, or 7.111.21. This incident highlights the importance of timely patching and proactive security measures for organizations utilizing Artifactory.