Cyber & AI intelligence
Wasteland.
Briefs indexed2377
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82329 2026-09-02

CVE-2026-82329: Unauthenticated Admin Takeover in JFrog Artifactory Lands on CISA KEV

"CISA added CVE-2026-82329, a CVSS 9.8 improper authentication flaw in JFrog Artifactory that hands unauthenticated network attackers administrative privileges under default configuration, to the Known Exploited…"

CISA added CVE-2026-82329, a CVSS 9.8 improper authentication flaw in JFrog Artifactory that hands unauthenticated network attackers administrative privileges under default configuration, to the Known Exploited Vulnerabilities catalog on September 2, 2026, with a three-day remediation deadline.

What Is It

JFrog Artifactory contains an authentication weakness (CWE-287) that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL), vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, and full compromise of confidentiality, integrity, and availability.

Why It Matters

CISA's KEV listing confirms active exploitation. The accompanying SSVC assessment scores the vulnerability as exploitation: active, automatable: yes, and technicalImpact: total, meaning attacks can be reliably scripted at scale and yield complete control of the affected instance. Known ransomware campaign use is currently listed as Unknown. The KEV entry flags this CVE as requiring forensic triage, which indicates responders should assume potential compromise rather than simply patching and moving on.

What's Vulnerable

Self-managed JFrog Artifactory across six release branches. Affected version ranges (fixed version listed as the upper bound):

Branch Affected Fixed in
Pre-7.111 < 7.111.21 (CPE match from 7.111.4) 7.111.21
7.117.x 7.117.0 – < 7.117.28 7.117.28
7.125.x 7.125.0 – < 7.125.20 7.125.20
7.133.x 7.133.0 – < 7.133.29 7.133.29
7.146.x 7.146.0 – < 7.146.38 7.146.38
7.161.x 7.161.0 – < 7.161.20 7.161.20

Patch Status

Fixed builds are available for every affected branch. CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines. Due date: September 5, 2026.

Sources