CISA has listed CVE-2026-82329 in its Known Exploited Vulnerabilities catalog, an authentication flaw in self-hosted JFrog Artifactory that can give an unauthenticated attacker administrative privileges.
What happened
JFrog published its advisory for CVE-2026-82329 on August 28, 2026 and rates it Critical. According to the CISA catalog entry, added September 2 with a federal due date of September 5, the flaw can under default configuration let an unauthenticated attacker with network access obtain administrative privileges. Fastly’s threat research team reported that scanning began within days of disclosure. It saw roughly 75,000 attempts on August 31, most of them from offensive security services, and a sharp rise on September 1 after a public exploit appeared. The JFrog advisory lists affected ranges across six Artifactory release lines, from 7.111 through 7.161.
Why it matters
An artifact repository holds the build outputs and dependencies that software teams pull into production. Fastly notes that an attacker with administrative control of a registry can reach stored credentials, create users and repositories, and tamper with published artifacts. That places the flaw in the software supply chain, where a compromise reaches every build that trusts the repository, not one server.
Our read
Most patch programs rank systems by exposure to the internet and treat an internal build tool as lower priority. An Artifactory instance is a tier-zero system in practice, because its integrity decides what every pipeline builds. Defenders who patched after September 2 should not stop at a version check. The catalog entry carries CISA’s forensic triage requirement, and the sensible reading is that admin tokens minted before the fix need reviewing and any credentials stored in the instance should be rotated. We covered how CISA deadlines are outrunning patch adoption, and this listing shows the gap applies to build infrastructure as much as to edge devices. Our piece on attackers targeting management consoles makes the related case for control planes.
Source: JFrog Security Advisories