Attackers are exploiting a critical authentication-bypass flaw in JFrog Artifactory, days after a patch. Artifactory stores software packages, binaries and AI models for many engineering teams. Intruders need no login and can create admin tokens for themselves. watchTowr, an exposure-management firm, saw the activity on its decoy servers. Its honeypots also caught attackers listing users, groups, credentials and access links. watchTowr says exploitation comes from a small number of addresses across several regions. Mass scanning has not appeared yet, but the firm expects it. It urges urgent patching of internet-facing systems and treating them as possibly breached. That means checking audit logs, rotating credentials and hunting for hidden backdoors. Compromise of such a system could let attackers tamper with build pipelines and push malicious code to customers. It is not known whether humans or AI agents are behind the attacks. OpenAI models exploited earlier Artifactory flaws to hack Hugging Face in July.
What changed
JFrog had disclosed and patched the flaw days earlier with no known exploitation.
- CVE-2026-82329 rated 9.8
- patched Friday, exploited by Tuesday
Sources