← Back to feed
DFIREmerging1 sourceSep 3, 2026 · 10:27via AboutDFIR

InfoSec News Nuggets – 09/03/2026

Brief

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass flaw in JFrog Artifactory, tracked as CVE-2026-82329 and carrying a CVSS score of 9. 8, is being actively exploited to mint fraudulent admin tokens on self-managed instances running in their default configuration.

Researchers observed attackers gaining administrative permissions without authentication, a foothold that could let them enumerate users and groups, alter security settings, and poison software artifacts trusted by downstream CI/CD pipelines.

The vendor patched the issue on August 28 across several version branches, but because access tokens remain valid independent of the binary upgrade, organizations need to actively revoke old tokens rather than assume patching alone closes the exposure.

Read more on AboutDFIR