News

JFrog Artifactory auth bypass under active exploit, patch now

JFrog patched a critical Artifactory authentication bypass, CVE-2026-82329 (CWE-287), that can hand an unauthenticated network attacker admin access under default settings. Fixed self-hosted builds are 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20; JFrog Cloud is already fortified. Researchers and trade press report active exploitation.

JFrog Artifactory auth bypass under active exploit, patch now

JFrog has patched a critical authentication flaw in Artifactory, tracked as CVE-2026-82329, and security researchers now say attackers are exploiting it in the wild. The fix and the impact come straight from JFrog's security advisory, published on August 28. The active-exploitation claims come from watchTowr and trade-press reporting in the days after, not from the advisory's own wording, so treat the urgency as real but keep the two sources separate.

What the flaw does

The advisory rates the bug Critical and classes it as improper authentication (CWE-287). Under a default Artifactory configuration, it can let an unauthenticated attacker who can reach the server over the network gain administrative privileges. That is what makes this a patch-tonight item: no login required, and the payoff is admin on your artifact repository, which for many teams is the spine of the software supply chain.

The builds that actually fix it

The patched self-hosted builds are 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20. Move to the fixed build on your release branch. One trap: a build that only cleared an earlier Artifactory issue can still sit below this fix. For example, 7.146.35 and 7.161.16 closed a separate path-traversal bug we covered when CISA added it to KEV, and both are older than the builds that fix this authentication flaw. If your team saw 7.146.37 on a list somewhere, do not rely on it; the fixed line is 7.146.38.

JFrog says the affected cloud environments are already fortified, so JFrog Cloud customers have no action to take. The exposure that needs attention is self-hosted Artifactory. Confirm the build each of your instances is running and upgrade the ones below the fixed line for their branch.

The takeaway

This is the same shape as recent emergency-patch stories, from SonicWall's SMA 1000 zero-days to the PaperCut NG/MF emergency patch: a single reachable box, a critical fix, and a narrow window before opportunistic scanning finds you. Do not wait for CVE-2026-82329 to land on a federal deadline list. Inventory your self-hosted Artifactory tonight, upgrade anything below the six fixed builds, and rotate admin credentials and tokens on any instance that was internet-reachable before you patched.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free