- Sources: Wiz report, CISA KEV catalog, HN submission
- Summary: Wiz, in a post dated 2026-09-10, reports exploitation against self-hosted Artifactory from 2026-08-15 to 2026-09-08 chaining CVE-2026-42018, which exposes an anonymous-user token, with CVE-2026-42016, which escalates it, and states that in some instances actors moved from the first request to a created admin account in under five minutes. A separate critical bypass, CVE-2026-82329, was exploited concurrently from 2026-09-01 to 2026-09-08, with Wiz reporting successful exploitation by several threat actors through a single unauthenticated POST to
/access/api/v1/registry/join that returns an admin-scoped token, and it affects Artifactory in its default configuration. Wiz states 59 percent of organizations remained vulnerable to CVE-2026-42016 six weeks after disclosure and CVE-2026-42018 declined only from 69 to 62 percent over four weeks, while the critical CVE-2026-82329 fell from 67 to 49 percent within two weeks, and fixed versions are 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20 or later. - Why it matters: Artifactory holds the artifacts, credentials and integrations of every build pipeline that depends on it, and the exposure Wiz measures is current rather than historical.
- Follow-up: Whether JFrog publishes its own incident detail, and whether the remaining unpatched share falls before the 2026-09-25 federal due date.
send feedback on this story