Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Executive Summary

Threat actors are exploiting a newly patched critical flaw in JFrog Artifactory (CVE‑2026‑82329, CVSS 9.8) that allows authentication bypass and creation of admin tokens. The vulnerability was publicly disclosed and patched, yet attackers are minting admin credentials just days later, highlighting the rapid exploitation cycle.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-01T17:53:11+00:00 - Category: threat-intel

Original Description: Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. "JFrog Artifactory contains an authentication weakness that, under default

"He that is giddy thinks the world turns round."

— William Shakespeare
Source: The Hacker News