# Attackers exploit Artifactory authentication-bypass flaw

_Tuesday, September 1, 2026 at 1:53 PM EDT · Security · Latest · Tier 1 — Major_

![Attackers exploit Artifactory authentication-bypass flaw — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0o8dDcHW4CJBLnXfYzfofbG1w0Fi4zCPqcjEgASsL0gXnESv5isMONZgXzek2rM3VwkhnEqz2K4whDwB_lFylCYvfXASQmsQSPA-8U25998PBT2Xopdaaj9_iG0XqdBPu6iXRmtlN2CGc8b5mv3t68CVxV2HYneRkiUhUu3EIgSogEgipzJUiymLfl0NQ/s1700-nu-rw-lo-l85-e365/jfrog.jpg)

Threat actors began exploiting CVE-2026-82329 in JFrog Artifactory on September 1, according to watchTowr. The critical authentication-bypass flaw can allow an unauthenticated network attacker to obtain administrative privileges under default configuration. WatchTowr said exploitation has included minting administrator tokens and enumerating users, groups, credential sets and federated-access topologies. JFrog released Artifactory 7.161.20 on August 28 to patch the issue; several prior release ranges are affected.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html)

---
Canonical: https://techandbusiness.org/newswire/A2N3k7FEtS8qexgetxqWhr
Retrieved: 2026-09-02T05:55:57.207Z
Publisher: Tech & Business (techandbusiness.org)
