CuraSec

Act active

Critical JFrog Artifactory auth bypass exploited to forge admin tokens

2026-09-03 14:58 UTC · BleepingComputer · read the source ↗ #artifactory#supply-chain#cve
  • Engineer — Act: JFrog Artifactory is a core CI/CD artifact store in most cloud-native stacks; this auth bypass (CISA KEV listed, public PoC on GitHub) allows attackers to mint admin tokens and poison artifact repositories. Patch Artifactory to the vendor-fixed version immediately, rotate all existing API tokens, and audit recent token-creation events in Artifactory access logs for unauthorized entries.
  • SOC/IR — Act: Active exploitation with CISA KEV listing means assume-breach posture for any org running Artifactory; hunt Artifactory audit logs for unexpected admin-token creation events since the CVE disclosure date, and watch for anomalous package downloads or uploads that may indicate a poisoned repository. Map activity to ATT&CK T1195 (Supply Chain Compromise) and T1550.001 (token abuse).
  • Leader — Act: A compromised Artifactory instance is a direct supply-chain risk — malicious packages could propagate to production software. Confirm this week whether your environment runs JFrog Artifactory and that your engineering team has applied the emergency patch; if Artifactory is customer-facing or feeds external releases, prepare a brief for stakeholders on exposure status.
  • Signals: CVE-2026-82329 — CISA KEV: listed, EPSS 0.08, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.