← Back to feed
DFIREmerging1 sourceSep 11, 2026 · 10:50via AboutDFIR

InfoSec News Nuggets – 09/11/2026

Brief

Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329

Wiz Research identified active exploitation of three JFrog Artifactory vulnerabilities that attackers are chaining to bypass authentication and gain full administrative control of self-hosted repository servers between August 15 and September 8.

One chain combines an authentication flaw that improperly hands out an internal anonymous-user token with a token-scope validation bug that lets attackers swap it for admin-level access, while a separate critical flaw, CVE-2026-82329, offers unauthenticated attackers a direct path to admin privileges via a single crafted request to the registry-join endpoint.

Read more on AboutDFIR