"Patching velocity has been slow," Wiz security researchers warned — and their telemetry shows why that warning matters.
Three separate flaws in JFrog Artifactory have been weaponized in the wild after fixes were published, allowing attackers to obtain administrative control of vulnerable, internet-exposed instances. The vulnerabilities are CVE-2026-42018 (a high-severity improper-authentication flaw patched on August 12), CVE-2026-42016 (a high-severity privilege-escalation bug patched on July 27), and CVE-2026-82329 (a critical authentication-bypass vulnerability patched on August 28). Researchers from Wiz and observers operating honeypots have documented active exploitation and post-compromise activity across multiple environments.
How attackers chained CVE-2026-42018 and CVE-2026-42016
Between August 15 and September 8, Wiz observed multiple attackers chaining CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances to gain admin access. According to Wiz, many intruders then deployed a custom Rust backdoor to establish command-and-control (C2) capabilities.
With administrative control, attackers performed a range of follow-on actions: creating persistent admin accounts; installing Groovy plugins to achieve remote code execution on the server; executing shell commands through the plugin for reconnaissance; scanning for sensitive files; delivering second-stage payloads; and uploading web shells. The activity pattern demonstrates attackers using administrative control to move from compromise to persistence and further intrusion within affected environments.
Exploitation of CVE-2026-82329: rapid activity after disclosure
CVE-2026-82329 is a critical authentication-bypass flaw that allows unauthenticated attackers with network access to obtain administrative privileges; JFrog published a patch for it on August 28. Security researchers told The Register that miscreants began battering internet-exposed systems vulnerable to CVE-2026-82329 just four days after JFrog disclosed the bug.
Wiz reported seeing “several” attackers exploiting CVE-2026-82329 between September 1 and 8. Those intrusions were not a single unified attack chain by one actor; instead, researchers observed multiple illicit behaviors including exfiltration of configuration details, establishing persistent admin accounts, token minting for long‑lived credentials, stealing keys, attaching attacker SSH keys to created users in some cases, and enumerating users, repositories and tokens.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadPatch adoption: the numbers that explain 'slow'
Wiz’s telemetry paints a stark picture of incomplete remediation even weeks after fixes were published. Six weeks after JFrog disclosed CVE-2026-42016, 59 percent of organizations remained vulnerable. Four weeks after CVE-2026-42018 was disclosed, 62 percent remained vulnerable. Organizations were quicker to remediate the critical CVE-2026-82329, but 49 percent remained vulnerable two weeks after its publication.
Wiz summed up the shared observation: attackers did not begin exploiting any of these CVEs until after JFrog issued fixes. Meanwhile, JFrog has not responded to The Register’s inquiries about attacks against any of the three CVEs.
watchTowr honeypot data and researcher confirmations
Independent telemetry reinforces Wiz’s findings. watchTowr’s honeypot network recorded attackers creating administrative credentials and enumerating users, groups, credential sets and federated access topologies. Yordan Ganchev, principal threat intelligence specialist at watchTowr, reported those enumeration activities as part of the intruder behavior observed after compromise.
Wiz researchers additionally “confirmed in-the-wild exploitation of all three vulnerabilities across multiple environments,” a confirmation that ties the honeypot signals to broader operational compromises.
What this means for technologists, procurement leaders, and adversaries
- Technologists and security teams: Wiz advises — and researchers recommend — upgrading to a fixed Artifactory version as soon as possible; prioritize remediation of internet-accessible Artifactory instances, restrict network access to trusted users and systems, and review Artifactory authentication and administrative activity for unexpected privileged access.
- Affected enterprises and procurement leaders: slow patching metrics (49–62 percent still vulnerable across the three CVEs within weeks) underline the need to track third-party component patching and to validate that vendors and internal teams apply critical fixes promptly for internet-facing infrastructure.
- Adversaries and threat actors: observed behaviors—installation of a Rust backdoor, Groovy plugin misuse for RCE, token minting, key theft and SSH key attachment—show a consistent preference for converting initial access into durable administrative control and credential artifacts that support long-lived presence.
One clear through-line from the data: disclosure and patch publication did not eliminate exploitation — they preceded it. For defenders that means prioritizing the simple but critical step the researchers emphasize: install the patched Artifactory releases immediately, isolate internet‑accessible instances where possible, and hunt for signs of the post-exploitation behaviors observers have already recorded. JFrog’s silence in response to The Register’s inquiries leaves a live operational question about how widely fixes have been deployed and how fast that can change the current risk picture.




