Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens
Attackers are actively exploiting a critical authentication bypass vulnerability in JFrog Artifactory, a widely used software repository platform, just days after the company disclosed the flaw and released patches. The vulnerability, tracked as CVE-2026-82329, allows unauthenticated attackers with network access to gain administrative privileges on affected self-hosted systems under default configurations. JFrog disclosed the vulnerability on August 28, 2026, and issued fixes for affected self-hosted versions. By September 1, security researchers at watchTowr reported observing exploitation in the wild. The flaw carries a critical CVSS score of 9.8 and resides in JFrog Access, the component responsible for issuing and validating credentials. According to watchTowr, instances without an additional join key configured receive a "phantom join key" that attackers can abuse to forge access and create administrator-level credentials. "This moved from disclosure to real-world exploitation with uncomfortable efficiency," said Yordan Ganchev, principal threat intelligence specialist at watchTowr.