Mathew Potter
Security Analyst
Your build pipeline trusts Artifactory for jars, containers, and deploy keys. Attackers noticed. September brought confirmed in-the-wild exploitation against self-hosted JFrog Artifactory, including a CVSS 9.8 authentication bypass that mints administrative access tokens with a single unauthenticated HTTP request.
CVE-2026-82329 is the headline: under default configuration, a remote attacker can POST to /access/api/v1/registry/join and receive HTTP 201 with an admin-scoped token in the response. Fastly logged exploitation climbing from scattered probes to more than 400,000 attempts in a single day after public exploit code appeared.
Wiz Research separately documented attackers chaining CVE-2026-42018 and CVE-2026-42016 to escalate a low-privilege anonymous token to full admin scope. Post-exploitation looks like real operator work: new persistent admin users, Groovy plugins for code execution, configuration exfiltration, SSH keys glued onto created accounts, and custom Rust backdoors for command and control.
CISA added the Artifactory flaws to KEV with federal remediation dates in September. JFrog Cloud was patched automatically. Self-managed installs are where the pain concentrates.
Artifactory often sits behind a VPN in documentation and on the public internet in reality. It holds secrets that never made it to a proper vault. Compromise there is a supply-chain event: malicious artifacts ship downstream, CI variables leak, and defenders chase endpoint alerts while the root cause lives in the repo server.
Industry stats quoted in The Register suggested many organizations remained on vulnerable builds weeks after disclosure. Patch velocity for developer tooling still lags ERP and email by a full quarter in most environments we review.
Artifact servers are production systems even when only developers log in. Forensic Five helps Canadian organizations map external exposure, review CI and registry configuration, and produce evidence for insurers and clients. We are based in St. Albert, Alberta. Scoped work, no vendor partnerships muddying the report.
Security Analyst
Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.