Skip to main content
Security Products

Wiz reports attackers chained JFrog Artifactory flaws to gain admin control

Wiz reports attackers chained JFrog Artifactory flaws to gain admin control Image: Primary
Wiz said it observed attacks between August 15 and September 8 in which intruders chained two JFrog Artifactory flaws to take administrator control of self-hosted servers and plant backdoors. CVE-2026-42018 hands an internal anonymous-user token to an unauthenticated caller; CVE-2026-42016 then lets that low-privilege token be exchanged for one with administrator scope because Artifactory does not check the token's permissions. In some cases attackers reached a new administrator account in under five minutes, and actions appeared in logs as token:anonymous. JFrog had fixed both flaws before the observed attacks, so only unpatched servers were exposed. Wiz also reported separate exploitation of critical authentication bypass CVE-2026-82329, rated 9.8, on six release branches up to 7.161.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital Products
Capital Products

Copenhagen's Seed Capital closes €130M Fund V, expands to Nordics

Seed Capital, a Copenhagen-based seed investor founded in 2004, said it closed its fifth fund at €130 million. The fund will write first checks of €3-6 million into 15-17 companies in fintech, cybersecurity, resilience and AI-dri...

AI Products
AI Products

Google releases Gemini desktop app for Windows 10 and 11

Google launched a Gemini desktop application for Windows, available globally today for Windows 10 and 11, the company said in a blog post. The app opens over active work with the Alt + Space keyboard shortcut and provides a dedic...

Products
Products

Hermeus unveils Ramjet-X high-Mach test vehicle to fly on Quarterhorse

Hermeus has unveiled plans for Ramjet-X, a high-Mach test vehicle designed to be carried aloft by a supersonic variant of its Quarterhorse aircraft and released at ignition speeds. The company says Ramjet-X will offer a "Flight T...

AI
AI

OpenAI reports elevated ChatGPT errors for European users

OpenAI said ChatGPT users in Europe were experiencing elevated errors, according to a status page incident. The company identified the problem at 07:53 UTC on September 11, 2026, and said it was implementing a mitigation. By 08:3...