Act
active
Critical JFrog Artifactory auth bypass exploited to forge admin tokens
- Engineer — Act: JFrog Artifactory is a core CI/CD artifact store in most cloud-native stacks; this auth bypass (CISA KEV listed, public PoC on GitHub) allows attackers to mint admin tokens and poison artifact repositories. Patch Artifactory to the vendor-fixed version immediately, rotate all existing API tokens, and audit recent token-creation events in Artifactory access logs for unauthorized entries.
- SOC/IR — Act: Active exploitation with CISA KEV listing means assume-breach posture for any org running Artifactory; hunt Artifactory audit logs for unexpected admin-token creation events since the CVE disclosure date, and watch for anomalous package downloads or uploads that may indicate a poisoned repository. Map activity to ATT&CK T1195 (Supply Chain Compromise) and T1550.001 (token abuse).
- Leader — Act: A compromised Artifactory instance is a direct supply-chain risk — malicious packages could propagate to production software. Confirm this week whether your environment runs JFrog Artifactory and that your engineering team has applied the emergency patch; if Artifactory is customer-facing or feeds external releases, prepare a brief for stakeholders on exposure status.
- Signals: CVE-2026-82329 — CISA KEV: listed, EPSS 0.08, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.