Attackers Pounce on Critical Artifactory Bug Following Disclosure

ExploitedCriticalDark Reading · Jai Vijayan·

CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what NexaPulse adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

At a glance

Severity
Criticalfrom category and source signals; no CVSS referenced
Exploitation
Confirmed — 1 of 1 referenced vulnerability is on the CISA Known Exploited Vulnerabilities catalogue
Vulnerabilities
CVE-2026-82329
Vendors & products
None named
Threat actors & malware
None named
Industries
Manufacturing
Coverage
1 outlet· first seen 2026-09-01 21:05 UTC
Priority
64/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Vulnerabilities referenced

  • CVE-2026-82329Exploited· due 2026-09-05

    JFrog Artifactory

    JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

    Added to KEV 2026-09-02

    Full record →

Coverage

One outlet has carried this so far.

  1. Dark ReadingEstablished SourceFirst reported

    2026-09-01 21:05 UTC

Related stories