<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Artifactory (&lt; 7.133.11) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/artifactory--7.133.11/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 11 Sep 2026 06:51:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/artifactory--7.133.11/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Active Exploitation of JFrog Artifactory Vulnerabilities</title><link>https://feed.craftedsignal.io/briefs/2026-09-artifactory-exploit-chain/</link><pubDate>Fri, 11 Sep 2026 06:51:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-artifactory-exploit-chain/</guid><description>Attackers are actively exploiting a chain of three critical vulnerabilities (CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329) in JFrog Artifactory to bypass authentication and achieve full administrative control.</description><content:encoded><![CDATA[<p>Wiz Research has disclosed active, in-the-wild exploitation of three vulnerabilities affecting JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329. Threat actors are utilizing these vulnerabilities in a chained attack sequence to circumvent authentication mechanisms. By leveraging this chain, unauthorized remote attackers gain complete administrative access to compromised Artifactory instances. This is a high-priority threat, as Artifactory typically hosts sensitive build artifacts and secrets, making it a lucrative target for lateral movement and supply chain compromise. Organizations running JFrog Artifactory must treat these CVEs as critical and prioritize patching or isolating instances until remediation is applied.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain administrative control over JFrog Artifactory instances. This level of access grants the attacker full control over stored artifacts, repository management, and potentially integrated secrets, enabling downstream supply chain attacks, code modification, and broader network compromise. Given the prevalence of Artifactory in CI/CD pipelines, impact is significant for enterprises relying on centralized artifact management.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch all JFrog Artifactory instances immediately to versions addressing CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329.</li>
<li>Restrict network access to Artifactory administrative interfaces, ensuring they are not exposed to the public internet.</li>
<li>Review Artifactory access logs for unusual administrative logins or requests originating from non-authorized internal IP ranges.</li>
<li>Rotate credentials and API keys managed or stored within the Artifactory instance if compromise is suspected.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>supply-chain</category><category>vulnerability</category><category>authentication-bypass</category></item></channel></rss>