← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 2, 2026 · 12:24via CSO Online

Exploited JFrog Artifactory bug puts software supply chain on alert

Brief

A critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data.

The flaw, tracked as CVE-2026-82329 , was disclosed by JFrog on August 28 and can, under default configuration, allow an unauthenticated attacker with network access to obtain administrative privileges.

By September 1, watchTowr said its Attacker Eye honeypot was already seeing threat actors exploit internet-exposed systems. The activity included attackers minting administrator tokens and enumerating users, groups, credential sets and federated access topologies.

“This moved from disclosure to real-world exploitation with uncomfortable efficiency,” said Yordan Ganchev , principal threat intelligence specialist at watchTowr.

Read more on CSO Online