Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Critical JFrog Artifactory flaw exploited days after patch, attackers mint admin tokens

Just after JFrog released a patch for the critical CVE-2026-82329 authentication bypass, threat actors began exploiting exposed Artifactory servers and creating new admin credentials.

JFrog announced a critical authentication-bypass bug in Artifactory (CVE-2026-82329) and issued a patch on Friday. By Tuesday, security teams reported that unauthenticated intruders were already exploiting publicly accessible installations, minting administrative tokens and enumerating users, groups and federated access configurations. watchTowr’s threat-intel unit captured the activity on its honeypot network, noting a small set of IP addresses from diverse locations targeting multiple decoys.

While large-scale scanning has not yet materialized, the analysts expect it to expand soon. They advise any entity running vulnerable versions to apply the fix, treat exposed systems as potentially compromised, rotate all credentials and scrutinize audit trails for abnormal changes. Gaining admin control of a software-supply-chain hub could allow attackers to tamper with build pipelines, move laterally into production environments and inject malicious code downstream to customers.

Why it matters

Compromise of Artifactory can let attackers alter software supply chains, affecting countless downstream users.

In this story

CVE-2026-82329Artifactoryauthentication bypassadmin tokensupply chainpatchthreat intelligencehoneypotexploitation
Get the beta ↗