Security News

Cybersecurity news aggregator

CRITICAL Attacks Dark Reading

Attackers Pounce on Critical Artifactory Flaw Following Disclosure

CVE-2026-82329 is a critical (CVSS 9.8) authentication bypass flaw in JFrog Artifactory that allows unauthenticated attackers to gain administrative access without user interaction. The article states threat actors are actively exploiting this vulnerability in default configurations. Specific affected and fixed version numbers are not provided in the article text, and the provided NVD data pertains to a different CVE (CVE-2025-29927) for Vercel Next.js.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Application Security Attackers Pounce on Critical Artifactory Flaw Following Disclosure Attackers Pounce on Critical Artifactory Flaw Following Disclosure by Jai Vijayan Sep 1, 2026 4 Min Read Vulnerabilities & Threats Critical Langflow Flaw Exploited as Attacks on AI Platform Rise Critical Langflow Flaw Exploited as Attacks on AI Platform Rise by Rob Wright Sep 1, 2026 3 Min Read World Related Topics DR Global Asia Pacific Europe Latin America Middle East & Africa Recent in World See All Cyberattacks & Data Breaches Russian Hackers Phish EU Officials Over Messaging Apps Russian Hackers Phish EU Officials Over Messaging Apps by Nate Nelson Aug 27, 2026 5 Min Read Cyberattacks & Data Breaches Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office by Nate Nelson Aug 14, 2026 4 Min Read The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Application Security Cyber Risk Threat Intelligence Vulnerabilities & Threats News Attackers Pounce on Critical Artifactory Flaw Following Disclosure CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems. Jai Vijayan , Contributing Writer September 1, 2026 4 Min Read Source: hapabapa via Getty Images Threat actors are actively exploiting a critical JFrog Artifactory vulnerability just days after its public disclosure, putting a fresh spotlight on the software repository platform after OpenAI's AI agents exploited zero-day flaws in the repository manager during their attack on Hugging Face earlier this year. CVE-2026-82329 is a critical (CVSS: 9.8) authentication bypass vulnerability in default configurations of Artifactory that an unauthenticated attacker can exploit to gain administrative access to the platform, with no user interaction required. Flaw Enables Administrative Privileges In a worst case scenario, an attacker with administrative privileges on a vulnerable Artifactory instance would gain broad control over an organization's repositories, artifacts, users/tokens, and configuration. They could use the access to potentially steal or tamper with software packages and other build artifacts. JFrog disclosed the vulnerability on Aug. 28 and released patched versions of the software. Related: 'HTTP Terminator' Hunts for Novel Desync Attacks Three days later, on Aug. 31, watchTowr reported observing exploit activity targeting CVE-2026-82329. Meanwhile, cybersecurity Pruva and ethical hacker Souhaib Naceri said they were able to readily reproduce the bug. Pruva also published a proof-of-concept, raising the prospect of more widespread exploitation. Yordan Ganchev, principal threat intelligence specialist at watchTowr, tells Dark Reading that the attacks appear to be originating from a small number of IP address from varying geographies and involves multiple threat actors. "Broad-scale scanning and mass exploitation has not been observed, but that is unlikely to stay the case for long," Ganchev says. Attackers Minting Admin Tokens According to Ganchev, telemetry from watchTowr’s global Attacker Eye honeypot network shows attackers are exploiting CVE-2026-82329 to mint administrator tokens and to enumerate users, groups, credential sets, and federated access topologies. "This moved from disclosure to real-world exploitation with uncomfortable efficiency," he says. JFrog Artifactory is a repository and artifact-management platform that many organizations use to store, manage, secure, and distribute software packages, as well as build artifacts such as container images, libraries, and binaries. JFrog has said some 6,600 organizations worldwide, including 83% of Fortune 100 companies use its platform currently. Artifactory was the software component that OpenAI's agents recently exploited to break out of a restricted security evaluation environment and gain Internet access, which ultimately led to the Hugging Face attack . During that escape, OpenAI's agents exploited one Artifactory vulnerability to make outbound requests and gain a path to the Internet and another privilege escalation vulnerability to obtain admin level access on Artifactory. OpenAI subsequently disclosed these previously unknown vulnerabilities to JFrog, which fixed the issues. Related: OWASP Flags Top AI Skill Risks in New Security Blueprint Not Related to OpenAI/Hugging Face Incident In a prepared statement, JFrog chief technology officer (CTO) and co-founder Yoav Landman made clear that exploitation of CVE-2026-82329 is not related to the OpenAI/Hugging Face incident. "It is improper authentication rather than RCE, and it does not affect the JFrog SaaS [software-as-a-service] platform, only self-hosted deployments," he said. He pointed to CVE-2025-29927 , a critical authentication bypass vulnerability in Next.js, as another example of a similar bug that affected only self-hosted apps and not the cloud hosted platform. JFrog's responsibility as a platform provider is to detect, remediate fast, and keep giving customers a clear path forward, Landman said. "In the long run, defenders win. The same AI that probes for weaknesses will find, patch, and harden faster than attackers can exploit." Related: OpenAI Adds Controls That Should've Been There Already Ganchev says what watchTowr has observed so far suggests that some of the ongoing attacks targeting the vulnerability are opportunistic, where bad actors probed for and exploited the CVE on vulnerable Artifactory systems but stopped there. "Other attempts successfully exploited the vulnerability and then probed/enumerated the JFrog Artifactory instances to discover if the environment was worth exploiting further," he says. Organizations running affected versions of JFrog Artifactory should urgently patch Internet-exposed systems. But patching alone is not enough, Ganchev adds. Customers should treat systems that were Internet exposed while vulnerable as potentially compromised already. "Defenders should inspect audit logs, rotate exposed credentials, and investigate connected systems for malicious changes or backdoor access," he advises. "When attackers gain admin level access of a central software supply chain system, they can do what every engineering team does best — build, ship and distribute software fast," he warns. "From there, they could tamper with build pipelines, move laterally into production systems and potentially push malicious changes downstream to customers." About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. See more from Jai Vijayan Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach Cloud Incident Response: Forensics in Distributed Environments Beyond the Login: Key Considerations for Evaluating Identity Security SASE Pivot and Trends 2026: A Gartner Keynote What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI More Webinars Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice Cyber Risk What We Missed: Delta Flight Disrupted With Wi-Fi Hack What We Missed: Delta Flight Disrupted With Wi-Fi Hack by Rob Wright , Alexander Culafi Aug 20, 2026 Cyberattacks & Data Breaches Agentic AI Presen

Share this article