JFrog security advisory (AV26-867) – Update 1

Used in attacksCriticalCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
Critical
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-82329
Reported by
1 outlet

As of August 28, 2026, JFrog is affected by a vulnerability in the following product:

  • Artifactory
    • Prior to 7.111.21
    • Prior to 7.117.28
    • Prior to 7.125.20
    • Prior to 7.133.29
    • Prior to 7.146.38
    • Prior to 7.161.20

Open-source reporting indicates that CVE-2026-82329 related to JFrog Artifactory is being exploited in the wild.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Update 1

On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-82329 to their Known Exploited Vulnerabilities (KEV) Database.

Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Vulnerabilities referenced

  • CVE-2026-823299.8Critical

    JFrog Artifactory

    JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

    Used in attacks

    Added to CISA's list 2026-09-02 · Patch or advisory available

    Full record →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber SecurityOfficial SourceFirst reported

    2026-09-02 18:55 UTC

Related stories