# Wiz reports Artifactory flaw chain exploited to plant Rust backdoor

_Friday, September 11, 2026 at 12:29 PM EDT · Security · Latest · Tier 2 — Notable_

![Wiz reports Artifactory flaw chain exploited to plant Rust backdoor — Primary](https://www.bleepstatic.com/content/hl-images/2025/03/12/hacker.jpg)

Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and exchanging it for an admin-scoped token.

In some cases an administrator account was created in under five minutes. Attackers then installed malicious Groovy plugins, deployed a Rust backdoor with command-and-control capability, stole configuration data and cluster join keys, and added SSH keys. Wiz estimates 49% to 62% of reachable Artifactory instances are vulnerable to at least one of three flaws, including CVE-2026-82329, an authentication bypass watchTowr observed being exploited earlier this month.

JFrog did not respond to a request for confirmation.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/)

---
Canonical: https://techandbusiness.org/newswire/fN1wsnc2sxUkzN0sq2fpBa
Retrieved: 2026-09-12T02:48:17.305Z
Publisher: Tech & Business (techandbusiness.org)
