11-09-2026
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
Report completeness: Low
Victims:
Organizations running jfrog artifactory, Self hosted jfrog artifactory instances
CVEs:
CVE-2026-42018 [Vulners]
CVSS V3.1: 7.5,
Vulners: Exploitation: Unknown
CVE-2026-42016 [Vulners]
CVSS V3.1: Unknown,
Vulners: Exploitation: Unknown
CVE-2026-82329 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- jfrog artifactory (<7.111.21, <7.117.28, <7.125.20, <7.133.29, <7.146.38)
TTPs:
Tactics: 2
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1059, T1059.004, T1068, T1078, T1083, T1105, T1136, T1190, T1505, T1505.003, have more...
IOCs:
IP: 19
Url: 2
Hash: 1
Algorithms:
sha1
Languages:
rust, groovy
Platforms:
intel