Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 (opens in a new tab)
Why readFirst hand telemetry on an active campaign chaining three Artifactory flaws, with the post exploitation artifacts you need to hunt for right now.
Wiz Research reports in the wild exploitation of CVE-2026-42016, CVE-2026-42018 and CVE-2026-82329 in JFrog Artifactory, chained to bypass authentication, escalate privileges and take administrative control. CVE-2026-42018 is the entry point: improper authentication causes Artifactory to hand an internal anonymous user token to an unauthenticated requester even where anonymous access is off. Post exploitation is what makes this urgent for hunters, with persistent administrator accounts created, malicious Groovy plugins deployed for code execution, and Rust based backdoors installed for persistence, all inside a system that holds an organization's build artifacts and therefore sits upstream of everything it ships.
Indicators16
- Hashes
513a907b69edffc3cb77a494da395178d21ef9bd- URLs
hxxp://log[.]gitclone[.]org:45678/smtphxxp://3[.]88[.]162[.]79:36789/smtp- Addresses
93[.]104[.]155[.]1333[.]88[.]162[.]79149[.]102[.]229[.]150186[.]247[.]79[.]240182[.]62[.]201[.]69146[.]19[.]216[.]120185[.]190[.]58[.]17245[.]61[.]176[.]88223[.]144[.]227[.]110129[.]121[.]56[.]23416[.]54[.]250[.]190105[.]188[.]75[.]16- Domains
log[.]gitclone[.]org