CVE-2026-42018Active Exploitation(jfrog / artifactory)

CRITICALCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch jfrog artifactory systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-25. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-287

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • artifactory

Threat summary

  • Active exploitation appears in 38 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 58 mentions across 15 observed days

What's happening

  • Active exploitation reported across 38 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 29 signals
  • Technical details provided in 41 signals
  • Disclosure: 5 classified signals
  • Peaked 10d ago at 11 mentions (2026-09-12); latest day: 1
  • 58 total mentions across 15 days

Affected systems

Vendors
Products
artifactory

Deep dive

Activity timeline58 mentions / 15d
036811Mentions · 2026-08-12: 1Mentions · 2026-08-14: 1Mentions · 2026-09-10: 1Mentions · 2026-09-11: 10Mentions · 2026-09-12: 11Mentions · 2026-09-13: 8Mentions · 2026-09-14: 9Mentions · 2026-09-15: 5Mentions · 2026-09-16: 2Mentions · 2026-09-17: 1Mentions · 2026-09-18: 3Mentions · 2026-09-21: 2Mentions · 2026-09-22: 1Mentions · 2026-09-25: 2Mentions · 2026-09-26: 1PoC Mentioned / Linked · 2026-09-11: 2PoC Mentioned / Linked · 2026-09-12: 1PoC Mentioned / Linked · 2026-09-13: 1PoC Mentioned / Linked · 2026-09-17: 1PoC Mentioned / Linked · 2026-09-18: 1Exploit Tool / Code · 2026-08-14: 1Exploit Tool / Code · 2026-09-12: 1Exploit Tool / Code · 2026-09-15: 1Exploit Tool / Code · 2026-09-17: 1Active Exploitation · 2026-09-10: 1Active Exploitation · 2026-09-11: 7Active Exploitation · 2026-09-12: 9Active Exploitation · 2026-09-13: 6Active Exploitation · 2026-09-14: 8Active Exploitation · 2026-09-15: 4Active Exploitation · 2026-09-17: 1Active Exploitation · 2026-09-18: 2Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-09-11: 7Patch / Workaround · 2026-09-12: 6Patch / Workaround · 2026-09-13: 7Patch / Workaround · 2026-09-14: 5Patch / Workaround · 2026-09-15: 2Patch / Workaround · 2026-09-18: 1Technical Details · 2026-08-14: 1Technical Details · 2026-09-11: 9Technical Details · 2026-09-12: 8Technical Details · 2026-09-13: 7Technical Details · 2026-09-14: 8Technical Details · 2026-09-15: 4Technical Details · 2026-09-16: 1Technical Details · 2026-09-17: 1Technical Details · 2026-09-18: 208-1208-1409-1009-1109-1209-1309-1409-1509-1609-1709-1809-2109-2209-2509-26
Signal classification6 categories
Active Exploitation
3669.2%
Patch
611.5%
Disclosure
59.6%
General
35.8%
Exploit
11.9%
PoC
11.9%
Referenced assets82 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-121
General1
2026-08-141
Exploit1
2026-09-101
Active Exploitation1
2026-09-1110
Active Exploitation6Disclosure2Patch1PoC1
2026-09-1211
Active Exploitation9Patch2
2026-09-138
Active Exploitation5General1Patch2
2026-09-149
Active Exploitation8Patch1
2026-09-155
Active Exploitation4Disclosure1
2026-09-162
Disclosure1General1
2026-09-171
Active Exploitation1
2026-09-183
Active Exploitation2Disclosure1
Full discourse20 posts
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🚨 JFROG ARTIFACTORY UNDER ACTIVE ATTACK — AUTH BYPASS LEADS TO ADMIN CONTROL AND BACKDOORS Wiz Research has confirmed active in-the-wild exploitation of THREE vulnerabilities affecting self-hosted JFrog Artifactory environments: * CVE-2026-82329 — Critical authentication bypass, CVSS 9.8 * CVE-2026-42018 — Anonymous-user token exposure * CVE-2026-42016 — Token scope validation / privilege escalation Attackers are using two different paths to obtain ADMINISTRATIVE CONTROL of vulnerable Artifactory servers. ATTACK PATH #1: CVE-2026-42018 → Obtain internal anonymous-user JWT → CVE-2026-42016 → Exchange it for an admin-scoped token → Create persistent administrator account Wiz observed attackers moving from the initial unauthenticated request to a newly created administrator account in UNDER FIVE MINUTES in some cases. ATTACK PATH #2: CVE-2026-82329 Under Artifactory's default configuration, an unauthenticated attacker can directly obtain administrative privileges. Wiz observed successful exploitation between September 1–8. 🚨 POST-EXPLOITATION ACTIVITY Once administrative access was obtained, attackers were observed: * Creating persistent admin accounts * Minting long-lived credentials * Stealing Artifactory configuration * Enumerating repositories, users and tokens * Extracting cluster join keys * Adding attacker-controlled SSH keys * Deploying malicious Groovy plugins * Executing arbitrary commands * Uploading web shells * Deploying custom Rust-based backdoors * Establishing external C2 communications This is particularly serious because Artifactory often sits directly inside the SOFTWARE SUPPLY CHAIN. A compromised Artifactory administrator potentially controls the repository infrastructure trusted by developers and CI/CD systems. ⚠️ EXPOSURE REMAINS HIGH According to Wiz telemetry, approximately 67% of organizations running Artifactory had at least one instance vulnerable to CVE-2026-82329 when it was disclosed. Two weeks later, approximately 49% remained vulnerable. ⚠️ Analyst Note: This isn't simply another vulnerable internet-facing application. Artifactory is part of the trust infrastructure behind software development. Internet → Artifactory auth bypass → Administrator access → Repository control → Build artifacts → CI/CD integrations → Potential software supply-chain compromise That makes administrative compromise particularly dangerous. JFrog has released patched versions. Organizations operating SELF-HOSTED Artifactory should upgrade immediately and investigate historical logs for exploitation rather than assuming patching alone resolves a previous compromise. JFrog Cloud environments were already remediated by JFrog and require no customer action for CVE-2026-82329. Original research — Wiz: https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-42018-cve-2026-82329 Official JFrog advisories: https://docs.jfrog.com/releases/docs/jfrog-security-advisories #DDW #JFrog #Artifactory #SupplyChain #CyberSecurity

    Post summary

    Wiz Research confirms in‑the‑wild exploitation of three CVEs in self‑hosted JFrog Artifactory, allowing attackers to gain administrative control and deploy backdoors. JFrog has issued patches and urges immediate upgrades.

    11020107.3K
    205.0K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added JFrog Artifactory vulnerabilities CVE-2026-42016 & CVE-2026-42018 and ConnectWise ScreenConnect vulnerability CVE-2026-84869 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/ygnhtKqllb

    Post summary

    The DHS KEV catalog now includes three new CVEs affecting JFrog Artifactory and ConnectWise ScreenConnect; the tweet directs users to apply mitigations to prevent active exploitation.

    1602138.1K
    302.7K followersView on X
  • Ryx@PadhiyarRushi
    Active Exploitation

    One empty cluster key = permanent Artifactory admin. CVE-2026-82329 (and the related chain CVE-2026-42018 + CVE-2026-42016): unauthenticated request mints admin-scoped tokens on self-hosted JFrog Artifactory. PoCs and toolkits are public. Wiz and watchTowr already saw live campaigns. CISA KEV has them. https://www.securityweek.com/three-jfrog-artifactory-flaws-exploited-for-backdoor-deployment/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #SupplyChain #AppSec

    Post summary

    The post warns of active exploitation of a critical Artifactory vulnerability chain (CVE-2026-82329), noting public PoCs/toolkits, live campaigns observed by security firms, and inclusion in the CISA KEV catalog.

    10043724
    924 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-42018 - high 🚨 JFrog Artifactory - Anonymous Token Disclosure via Trailing Slash Auth Bypass > JFrog Artifactory contains an information disclosure caused by returning an internal ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-42018 @pdnuclei #NucleiTe...

    Post summary

    The text announces CVE-2026-42018 as a high-severity information disclosure vulnerability in JFrog Artifactory, providing technical details and a link to a PoC (Nuclei template), but does not mention active exploitation or available patches.

    01033353
    1.3K followersView on X
  • VulnTracker@vuln_tracker
    Active Exploitation

    CVE-2026-42016, - 42018, - 82329: attackers are chaining three JFrog Artifactory flaws to gain full administrative control. Wiz observed attackers chaining an auth flaw (CVE-2026-42018) with a token scope-validation weakness (CVE-2026-42016) between August 15 and September 8 — creating persistent admin accounts in under 5 minutes, deploying malicious Groovy plugins, and installing Rust-based backdoors. A third flaw (CVE-2026-82329) allows unauthenticated admin token generation on default configs. 67% of organizations had a vulnerable instance exposed at disclosure. Patch now. Details: http://vulntracker.io/cves/CVE-2026-42016 #JFrog #Artifactory #CVE #SupplyChain #VulnTracker

    Post summary

    Attackers leveraged CVE‑2026‑42016, 42018, and 82329 to create admin accounts and install backdoors in JFrog Artifactory; the exploitation was observed by Wiz, and patches are now available.

    01042586
    772 followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに3件と1件の脆弱性を追加。 - JFrog Artifactory: CVE-2026-42016, CVE-2026-42018 - ConnectWise ScreenConnect: CVE-2026-84869 - GitLab: CVE-2026-85706 https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog

    Post summary

    CISA has added three CVEs for JFrog Artifactory, one for ConnectWise ScreenConnect, and a GitLab CVE to its catalog of known exploited vulnerabilities, confirming these vulnerabilities are actively used in real‑world attacks.

    110401.2K
    7.8K followersView on X
  • HOL@HashgraphOnline
    Active Exploitation

    Anyone who can reach your Artifactory Access API can turn an anonymous token into admin. CISA just put that chain on KEV. Attackers already planted backdoors with it. Patch self-hosted Artifactory, then hunt the trailing-slash token mint. https://hol.org/blog/cve-2026-42018-artifactory-anonymous-token-kev-chain https://t.co/Sx4TEGYQr0

    Post summary

    CISA has added CVE-2026-42018 to its KEV list, highlighting that attackers are already exploiting an anonymous-to-admin token elevation flaw in Artifactory, and a patch is recommended for self‑hosted instances.

    01140943
    19.1K followersView on X
  • 서버쟁이 놀이터@ueo0j
    Patch

    📊 9/13 통합 브리핑 개발 파이프라인이 이번 주 공격면의 중심이다. GitLab CVSS 10.0은 내일(9/14) KEV 마감이고, JFrog·ScreenConnect도 같은 주에 악용이 확인됐다. 말은 "속도 조절"인데 SpaceX·Oracle 쪽 자본은 반대로 움직인다. —— 오늘 먼저 —— ① GitLab CVE-2026-85706 — 내일(09-14) KEV 마감 자체 호스팅이면 19.1.8 / 19.2.6 / 19.3.2+. 패치 후 CI 변수·토큰·secrets.yml 회전 + 9/11 이전 접근 로그 포렌식. ② JFrog Artifactory · ScreenConnect — KEV, 실제 악용 CVE-2026-42016/42018(익명→관리자 체인)·CVE-2026-84869. 아티팩트 저장소·원격 접근 도구부터 버전·노출 확인. ③ Check Point VPN 2건 — 아직 악용 전 = 패치 창 CVE-2026-85102/85103 (CVSS 9.8 무인증 RCE). LivePatch Take 24 / Jumbo Hotfix. 네덜란드 NCSC "악용 임박". ④ GitHub Actions self-hosted — 내일(09-14) 브라운아웃 최소 버전 2.329.0. 9/14·16·18 등록·실행 차단, 9/25 전면. AMI·이미지·bootstrap까지 같이 올려야 CI가 안 멈춘다. ⑤ LiteLLM 예제 키 · Kiro/projen — 로컬·게이트웨이 위생 노출 LiteLLM 10곳 중 1곳이 sk-1234. Kiro 0.8.135+, projen 0.103.0+ 후 tasks.json 재생성. —— AI —— ──────── ▣ 🔴 Anthropic — 중국 7개 랩 '산업 규모' Claude 증류 공개 핵심: Alibaba·Moonshot·DeepSeek·Zhipu·MiniMax·Xiaomi·SenseTime 실명 지목. 최대 캠페인 GTG-16005(Alibaba 계열)는 5~7월 1억 5,100만 교환·피크 일 300만·위조 계정 3,500+. 제품 대응: 리셀러 차단, 응답 전 추론 요약, preserved thinking(다중 턴 추론 암호화). 왜 중요한가: 담론이 아니라 API 응답 형태가 바뀐다. 추론 토큰을 파싱·후처리하는 파이프라인은 오늘 재점검. 귀속·피해 규모는 Anthropic 자체 집계. https://www.anthropic.com/threat-intelligence-report-september-2026 ──────── ▣ Anthropic 위협 보고서 — GTG-10007 월 제로데이 후보 12건+ 핵심: 2025-12~2026-08, 7개 오용 영역. GTG-10007은 약 50개 조직 표적·한 달에 제로데이 후보 12건 이상. GTG-50014(ShinyHunters 계열)는 EC2 워커로 APK 180만·1TB+ 유출. 왜 중요한가: "AI가 공격 비용을 낮춘다"가 집계 가능한 숫자로 왔다. 에이전트 권한 경계·자격증명 노출·egress 통제를 다시 볼 근거. https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html ──────── ▣ Amodei 속도 조절 제안 · Altman 2026 IPO 부정 — 별개 사건 핵심: Amodei가 프론티어 페이스 조절을 제안. 같은 주 Altman은 안전 우려로 2026 IPO 부정을 시사하고 사내에서도 속도 조절 가능성을 언급(Bloomberg→Reuters). 구속력 있는 업계 합의는 없다. 왜 중요한가: "업계가 늦추기로 했다"는 요약은 틀리다. 같은 주 자본 집행은 반대로 감. 3번째 제안 항목(중국 공조 vs 칩 판매 제한)은 원문 간 충돌 — 인용 전 원문 대조. https://www.reuters.com/business/anthropic-ceo-urges-ai-companies-slow-model-development-2026-09-12/ ──────── ▣ Garry Tan — "미국 오픈웨이트 랩도 증류해야" 핵심: Anthropic 고발 직후 YC Garry Tan이 미국 오픈웨이트 진영도 프론티어 증류가 필요하다고 주장. 왜 중요한가: 같은 주에 "증류=탈취"와 "증류=전략"이 동시 출현. 법적 정의 없이 preserved thinking 같은 기술 방어가 규범보다 먼저 배치되는 중. https://techcrunch.com/2026/09/11/y-combinators-garry-tan-wants-u-s-open-weight-ai-labs-to-distill-frontier-models-too/ —— 클라우드·데이터센터·인프라 —— ──────── ▣ SpaceX 컴퓨트 리스 — 합산 연 411억 달러 핵심: Communacopia에서 신규 계약 연 133억(월 11.1억), 매출 인식 2026-12~. 고객 비공개. 기존 Anthropic·Google Cloud·Reflection과 합산 연 411억. 올해 네 번째 대형 AI 용량 계약. 왜 중요한가: 궤도·위성 컴퓨트가 실험이 아니라 가격표 있는 매출 라인. 지상 DC 전력·부지 제약의 대안 경로가 숫자로 열렸다. https://www.datacenterdynamics.com/en/news/spacex-signs-compute-contract-valued-at-133bn-annually/ ──────── ▣ Oracle FY2027 Q1 — OCI +121%, RPO $6,640억, capex $285억 핵심: 총매출 $193억(+30%), OCI $74억(+121%), RPO $6,640억, 분기 DC 850MW 추가, capex $285억(전년 $85억). GPU 약 30만 장 인도 보도(DCD). 왜 중요한가: RPO는 AI 수요가 계약으로 잠긴 가장 단단한 공시. 동시에 capex 3배+는 수익성 전환이 뒤로 밀린다는 뜻 — 둘을 같이 읽어야 한다. https://investor.oracle.com/investor-news/news-details/2026/Oracle-Announces-Q1-Results-Driven-by-Triple-Digit-Growth-in-Cloud-Infrastructure-Revenues/default.aspx ──────── ▣ Microsoft 2032년 38GW — Bloomberg 보도, 공식 확인 아님 핵심: 현재 ~12GW → 2032년 38GW 계획으로 보도. AI 전용은 현재 ~2GW에서 약 1/3까지. 자체+네오클라우드(CoreWeave·Nscale·Lambda 등) 병행. 왜 중요한가: 사실이면 Azure 용량 부족 완화 단서. 다만 Microsoft 미확인·인허가 변수 큼. "보도에 따르면"을 빼고 인용하면 오류. https://www.bloomberg.com/news/features/2026-09-10/microsoft-ai-focused-data-center-plan-to-add-26-gigawatts-of-compute ──────── ▣ UAE 5GW AI DC — 단일 캠퍼스에서 분산·방호로 재설계 핵심: 지역 공격 이후 아부다비 단일 캠퍼스 중심 계획을 다수 시설 분산으로 수정 검토. 지하화·방폭·방공까지 설계 요소로(Reuters). 왜 중요한가: AI 인프라 기준이 GPU·전력을 넘어 지정학·물리 복원력으로. DR에 "리전 소실" 시나리오를 넣을 공개 근거. https://www.reuters.com/world/middle-east/uae-revises-ai-data-center-plan-after-iranian-attacks-sources-say-2026-09-11/ —— 보안·규제 —— ──────── ▣ 🔴 EU CRA 의무 보고 — 어제(09-11)부터 법적 효력 핵심: EU 시장 디지털 요소 제품 제조사는 악용 중인 취약점·심각 사고를 ENISA SRP로 신고. CSIRT→ENISA→회원국 전파, 패치 전까지 비공개 원칙. OSS 스튜어드 의무는 2027-12-11~. 왜 중요한가: 담론이 아니라 어제부터의 법적 의무. 취약점 프로세스에 "EU 신고"를 넣고, 조기 공지 정책과 충돌 조항을 고쳐야 한다. https://www.enisa.europa.eu/news/the-cra-single-reporting-platform-is-launched ──────── ▣ Revolut — 위조 정부기관 데이터 요청에 고객정보 유출 핵심: 정상 기관처럼 위장한 fake emergency data request에 응답해 권한 없는 제3자에게 민감 고객정보 제공(Reuters). 왜 중요한가: 시스템이 아니라 "적법 절차"가 뚫렸다. 이메일 도메인 신뢰 배제, out-of-band·서명/포털 검증·2인 승인이 법무·데이터 요청 경로에 필요. https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/ ──────── ▣ LiteLLM 게이트웨이 — 노출 10곳 중 1곳이 예제 키 sk-1234 핵심: 기본 관리자 키를 그대로 둔 AI 게이트웨이에서 API 키·클라우드 접근 노출(The Hacker News). 왜 중요한가: LLM 게이트웨이는 자격증명 집중 지점인데 배포 위생이 못 따라감. 5분이면 확인되는 오늘 할 일. https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html —— 취약점·해킹 —— ──────── ▣ 🔴 GitLab CVE-2026-85706 — CVSS 10.0, 내일(09-14) 마감 핵심: commits API 경로 탐색+인증 누락 → 무인증 임의 파일 읽기. 영향 18.7+ ~ 19.1.8/19.2.6/19.3.2 미만. CISA 09-11 KEV·BOD 26-04 포렌식 트리아지. "공개 프로젝트 1개+" 조건에 기대지 말 것. 왜 중요한가: 소스·CI 시크릿이 대상. 패치만으로 끝이 아니라 시크릿 전면 회전+침해 점검이 완료 조건. 오늘의 1순위. https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog ──────── ▣ 🔴 JFrog Artifactory — KEV 체인, 공급망 직결 핵심: CVE-2026-42016(Incorrect Authorization)·CVE-2026-42018(Improper Authentication) 체인. 익명 토큰→관리자, 백도어 보고. CISA 09-11 KEV, 실제 악용 확인. 왜 중요한가: 아티팩트 장악=빌드 산출물 변조. GitLab(소스)+JFrog(아티팩트)가 같은 날 KEV에 오른 게 이번 주 구조. https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html ──────── ▣ 🔴 Cisco FMC — Qilin 랜섬웨어 연계, KEV 기한 경과 핵심: CVE-2026-20079(CVSS 10.0 인증 우회) 등. 3개 위협 클러스터 악용, Qilin 배포 확인. 연방 기한 09-12 이미 경과. 왜 중요한가: 방화벽 관리 평면이 뚫리면 뒤 네트워크 신뢰가 무너진다. 경계 장비 최우선. 패치+세션 무효화. https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html ──────── ▣ 🔴 Check Point VPN — CVSS 9.8×2, 패치 창이 열려 있음 핵심: CVE-2026-85102/85103 무인증 RCE. 공개 PoC·확인 악용 없음, 네덜란드 NCSC는 임박 경고. 09-09 LivePatch Take 24·Jumbo. 왜 중요한가: 경계 사전인증 RCE는 공개 후 수일 내 익스플로잇이 따라온다. 아직 악용 전인 지금이 여유 창. https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/ ──────── ▣ PaperCut — AI 에이전트 수백 개로 440+ 인스턴스 침해 핵심: CVE-2026-81578/82078 실제 악용. 러시아어권 공격자가 AI 에이전트 수백 개로 익스플로잇 개발. 긴급 패치→정식 릴리스 대체. 왜 중요한가: "AI로 만든 공격"이 마케팅이 아니라 피해 규모로 남음. GTG-10007과 같은 비용 곡선. https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html ──────── ▣ Microsoft 9월 패치 — 약 970건, 악용 중 제로데이 2건 핵심: 매체별 966~974건(집계 차이, 오보 아님). 악용 중 CVE-2026-81963(Update 스택 권한 상승)·CVE-2026-85880(ALPC). MS는 건수 폭증 원인으로 AI 기반 발견 도입을 듦. 왜 중요한가: "역대 최악"이 아니라 발견 방식 변경. 실무는 악용 중 2건에 집중. https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/ ──────── ▣ MikroTik RouterOS 2건 — KEV(09-10) 핵심: CVE-2026-67277(인증 누락)·CVE-2026-86060(명령 인자 인젝션). 악용 확인. 펌웨어 업그레이드+관리면·btest 인터넷 노출 차단. 왜 중요한가: 소규모·홈랩도 노출 여부부터. BOD 26-04 적용 대상. https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog ──────── ▣ Kiro IDE · projen — 리포가 개발자 PC 설정을 바꾼다 핵심: Kiro CVE-2026-89332(<0.8.135) — 조작된 리포가 Powers registry를 바꿔 workspace 데이터 유출. projen CVE-2026-89065/89066 — 경로 탐색·명령 삽입, 0.103.0+ 후 tasks.json 재-synthesize 필수. 왜 중요한가: 코딩 에이전트가 설정을 쓸 수 있다는 것 자체가 공격면. 리포·생성 설정 파일을 신뢰 경계 안에 두지 말 것. https://aws.amazon.com/security/security-bulletins/2026-111-aws/ —— 개발자·엔터프라이즈 —— ──────── ▣ ⏰ GitHub Actions self-hosted — 내일부터 브라운아웃 핵심: 최소 버전 2.329.0. 09-14·16·18 구형 러너 등록·실행 차단, 09-25 전면. 최신 릴리스 후 30일 내 업데이트 필요(GitHub 공식). 왜 중요한가: 보안 이슈가 아니라 날짜 확정 운영 중단. fleet·AMI·bootstrap을 오늘 확인하지 않으면 내일 CI가 멈춘다. https://github.blog/changelog/2026-06-12-github-actions-minimum-version-enforcement-timeline-for-self-hosted-runners/ ──────── ▣ Microsoft — Rust를 사내 Tier 1 언어로 승격 핵심: Windows 메모리 안전 취약점 제거 목표로 사내 개발자에게 Rust를 1급 언어로 제공(The Register). 왜 중요한가: 실험을 넘어 조직 표준. ~970건 패치와 나란히 읽으면 메모리 안전 구멍을 언어 차원에서 끊겠다는 맥락. https://www.theregister.com/devops/2026/09/11/microsoft-annoints-rust-as-a-tier-1-internal-language/5295732 ──────── ▣ GitHub Copilot 지표 — VS Code Agents 세션 포함 핵심: Enterprise/Org 1일·28일 보고서에 Agents 창 활성 사용자·세션·메시지 추가. 왜 중요한가: AI 코딩 측정이 채팅 사용률에서 실제 에이전트 활동으로 이동. 도입 효과 보고 기준을 갈아야 한다. https://github.blog/changelog/2026-09-11-add-vs-code-agents-to-copilot-usage-metrics/ ──────── ▣ Reuters×CuttingRoom — MCP로 뉴스룸 AI 영상 편집 핵심: Reuters MCP 서버+ShortCut 연결. 자연어로 검색·컷·믹싱·색보정·자막·포맷. 뉴스룸이 상호작용·데이터·규칙을 자체 통제. 왜 중요한가: MCP가 개발 도구를 넘어 엔터프라이즈 콘텐츠·데이터 연결 계층으로. tool policy·데이터 소유권 분리 참고 사례. https://www.reuters.com/media-center/reuters-cuttingroom-partner-provide-newsrooms-with-ai-assisted-video-editing-2026-09-12/ 패치 창은 며칠이 아니라 몇 시간이다. 소스·아티팩트·러너부터 오늘 끝내자. #IT브리핑 #GitLab #JFrog #CISA #KEV #CheckPoint #Anthropic #SpaceX #Oracle #EUCRA #GitHubActions #PaperCut #보안패치

    Post summary

    The briefing lists several critical CVEs, confirms active exploitation for some, and provides detailed patch timelines and mitigation steps across major platforms.

    100401.1K
    69 followersView on X
  • Nuvorlane@nuvorlane

    Cloudflare just pushed an emergency Managed Ruleset for WordPress and JFrog Artifactory — four new Block detections, no Log warm-up. CVE-2026-87902 is high-severity WordPress path traversal / LFI: unauthenticated reads of arbitrary host files (configs, system paths). A second WordPress rule covers XSS via comments. On Artifactory, CVE-2026-42018 and CVE-2026-82329 are critical auth bypasses — unauthenticated callers can skip controls and reach the instance. Edge virtual-patch buys time. It does not replace vendor patches on the origin. If those apps sit behind Cloudflare with the Managed Ruleset enabled, the new rules are already on Block. If you disabled Managed Rules or override to Log/Allow on related families, re-check today. Ops checklist: 1) Confirm Cloudflare Managed Ruleset is deployed (and not overridden) on zones that front WordPress or Artifactory 2) Patch WordPress and JFrog Artifactory to the latest vendor builds 3) Review Security Events for the new rule suffixes (...70a43f96, ...909a4db4, ...c797ef03, ...a813ac74) — spikes mean probes, not that the origin is fixed 4) Rotate secrets that live on those hosts if LFI/auth-bypass windows were open before the edge rule landed WAF rules close the public path. Patched origins close the residual path.

    10021118
    44 followersView on X
  • Safe Security@SafeCRQ
    Disclosure

    A few vulnerabilities worth having on your radar this week: → Cisco SEG CVE-2026-76461 - root RCE → GitLab CVE-2026-85706 - CI/CD secrets exposed → JFrog CVE-2026-42018 + 42016 - admin access → N-able CVE-2026-86218 - pre-auth RCE Full breakdown - https://safe.security/resources/blog/weekly-vulnerability-update-enterprise-systems-exploitation/?utm_source=linkedin&utm_medium=organic-social&utm_campaign=fy27q2_mkt-dg-osocial_organicsocial_080126 https://t.co/tKNR34V7Fd

    Post summary

    The post discloses four critical CVEs affecting enterprise software (Cisco, GitLab, JFrog, N-able) with brief technical impact descriptions (RCE, secret exposure, admin access) and directs readers to a blog for full details, without mentioning PoCs, exploits, active attacks, or patches.

    01021181
    3.2K followersView on X
  • Threat Landscape@LandscapeThreat
    General

    Most critical vulnerabilites so far september 2026 ●CVE-2026-85706 ●CVE-2026-20079 ●CVE-2026-20316 ●CVE-2026-82329 ●CVE-2026-42016 ●CVE-2026-42018 ●CVE-2026-85880 ●CVE-2026-85046 ●CVE-2026-81578 https://t.co/NY7w9mjxKz

    Post summary

    The text is a simple list of CVE identifiers for critical vulnerabilities from September 2026, lacking any specific details about exploits, patches, or technical characteristics.

    0103086
    76 followersView on X
  • CyberSignal | Cybersecurity & AI News@XQOPTRX
    Active Exploitation

    🚨 JFROG ARTIFACTORY UPDATE — ATTACKERS ARE CHAINING FLAWS, GAINING ADMIN ACCESS AND INSTALLING BACKDOORS CyberSignal Priority: 🔴 VERY HIGH ⚠️ SEPTEMBER 14 FOLLOW-UP — exploitation itself began earlier. Three Artifactory vulnerabilities are involved: CVE-2026-42018 CVE-2026-42016 CVE-2026-82329 The attack chain observed by Wiz is especially important: CVE-2026-42018 ↓ obtain internal anonymous-user token ↓ CVE-2026-42016 ↓ elevate token to ADMIN ↓ persistent administrator account ↓ malicious Groovy plugin ↓ arbitrary code execution ↓ second-stage payload / Rust backdoor CVE-2026-82329 can independently provide administrative access through authentication bypass. Observed post-exploitation activity reportedly included: → persistent admin creation → configuration theft → token minting → cluster-key theft → shell execution → web shells → SSH-key persistence → Rust C2 backdoors Why this matters: Artifactory can sit directly inside the SOFTWARE SUPPLY CHAIN. Compromising the system storing packages, binaries, containers and artifacts can provide much more leverage than compromising an ordinary server. 🛡️ Defender action Self-managed Artifactory users should prioritize patched branches immediately and investigate for persistence — not simply patch and move on. 🧠 CyberSignal insight Compromise the artifact repository... and you're standing dangerously close to everything the organization plans to ship. Sources: Wiz Research · JFrog · CISA · SecurityWeek September 14 update

    Post summary

    The text reports active exploitation of CVEs 2026-42018, 2026-42016, and 2026-82329 in JFrog Artifactory via an attack chain to gain admin access and deploy backdoors, with a verified need for patching.

    0101196
    215 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:週末のセキュリティ関連ニュース/記事】 <脆弱性> ・Check PointがVPNの重大な脆弱性を修正(CVE-2026-85102、CVE-2026-85103) https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/ ・GitLab、最大深刻度のパストラバーサル脆弱性にパッチ適用するようユーザーに促す(CVE-2026-85706) https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/ ・GitLabの脆弱性が公表翌日に悪用される(CVE-2026-85706) https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/ ・米CISAがJFrog Artifactory、ScreenConnect、MikroTik RouterOSなどの欠陥5件をKEVカタログに追加(CVE-2026-42016、CVE-2026-42018他) https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html ・Check Point VPNの重大な脆弱性は悪用の危険大、蘭NCSCが注意を呼びかけ(CVE-2026-85102、CVE-2026-85103) https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/ <マルウェア・その他脅威> ・ロシアのハッカー、マルウェアの検知回避目的でClaudeを使用 アンソロピックが発表 https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/ ・中国関連グループUNC3569がSogou Input Methodの欠陥悪用し、GRAYRABBITバックドアを展開(CVE-2021-38003) https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html ・GuardBreaker:コードのコメントを使い、AI活用したマルウェア分析を妨害 https://www.welivesecurity.com/en/business-security/guardbreaker-derailing-ai-assisted-malware-analysis-code-comment/ ・PCやMacに感染するClickFix攻撃が急速に拡大https://arstechnica.com/security/2026/09/clickfix-attacks-infecting-pcs-and-macs-are-going-viral/ ・パスキー関連のフィッシング攻撃でMicrosoft 365のデータが盗まれる https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/ <データ侵害/サイバー犯罪> ・Revolut、政府機関のメールアドレスを悪用した詐欺師に顧客データを提供 https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/ ・フロリダ州交通安全局、盗まれた警察アカウント経由でDMVデータベースの侵害被害を確認 https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/ ・VPNサービスSurfsharkのシステムが攻撃受ける https://www.securityweek.com/surfshark-systems-targeted-by-hackers/ ・Trezorのユーザー34万7,000人がフィッシングメールを受信 Brevoでインシデント発生後 https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/ ・英自治体が受けた攻撃、SonicWallの欠陥悪用した大規模キャンペーンと関連か(CVE-2026-15409) https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html ・JFrog Artifactoryの欠陥2件を連鎖して悪用する攻撃発生 管理者権限の取得後にバックドアが仕込まれる(CVE-2026-42018、CVE-2026-42016) https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html <AI関連> ・AI悪用が新たなフェーズへ:サイバー犯罪から監視、プロパガンダ、兵器利用まで ー アンソロピックが報告 https://securityaffairs.com/198905/ai/anthropic-ai-misuse-is-entering-a-new-phase-from-cybercrime-to-surveillance-propaganda-and-weapons.html ・アンソロピックCEO、AI業界は安全対策が追いつくための時間を確保すべきと発言 https://www.securityweek.com/anthropic-ceo-dario-amodei-says-ai-industry-needs-to-give-safety-measures-time-to-catch-up/ ・中国拠点のAI研究所7か所でClaude使った大規模な蒸留攻撃を実施 アンソロピックが発表 https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html ・AIは燃料やコストのために動物の命を犠牲にする傾向 https://www.theregister.com/ai-and-ml/2026/09/11/ai-more-likely-to-kill-animals-if-it-saves-fuel-or-money/5295993 ・AstraがAI使った攻撃のレベルを引き上げ 防御側にとって意味するものとは https://arcticwolf.com/resources/blog/astra-raised-the-bar-for-ai-enabled-attacks/ ・OpenAIのAIエージェントがRubyGemsを攻撃するキャンペーンに関与か RubyDocサーバーでRCEを実行 https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html ・Claudeユーザーが生物兵器の研究目的で安全対策の抜け道探る アンソロピックが複数の試みを阻止 https://arstechnica.com/ai/2026/09/claude-users-found-ways-around-safeguards-for-bioweapons-research/ <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・Contiランサムウェア開発者のウクライナ人、米裁判所で拘禁4年の実刑判決 https://www.securityweek.com/ukrainian-conti-ransomware-developer-sentenced-to-4-years-in-us-prison/ ・AT&Tの店舗従業員、SIMスワップで収入得たとして拘禁16か月の実刑判決 https://www.theregister.com/cyber-crime/2026/09/11/att-store-worker-gets-16-months-inside-for-sim-swap-side-hustle/5295898 <プライバシー> ・2,300万人が利用する人気旅行アプリ、軍人含むユーザーの行動が監視可能に https://cybernews.com/security/polarsteps-travel-app-exposes-users-soldiers/ <リサーチ/攻撃手法/TTP> ・「スキルポイズニング攻撃」でAIエージェントがマルウェアドロッパーに変貌 中国CVERCが警告 https://ministryofcyberaffairs.com/news/skill-poisioning-turning-ai-agents-into-malware-droppers-warns-china-s-national-cert-66b8bba4-9ffd-4583-a6c7-122e8149e0e8 ・Beltdown2:Cursor CLIサンドボックスに脱出経路が存在 https://www.accomplish.ai/blog/beltdown2-escaping-the-cursor-cli-sandbox/ <その他> ・FBIのサイバー部門責任者、同局初の非機密サイバー戦略を発表 https://federalnewsnetwork.com/cybersecurity/2026/09/fbi-cyber-leader-details-bureaus-first-unclassified-cyber-strategy/ ・EUサイバーレジリエンス法により、24時間以内の脆弱性報告が義務化 https://www.theregister.com/security/2026/09/11/eus-cyber-resilience-act-starts-the-24-hour-vulnerability-clock/5295821

    Post summary

    The tweet aggregates security news highlighting several CVEs, many of which have been patched but are already seeing active exploitation (e.g., Check Point VPN flaws, GitLab path traversal, JFrog Artifactory chain flaws) as noted by CISA’s KEV catalog and rapid post‑disclosure attacks.

    000301.0K
    1.3K followersView on X
  • Shogo Katsurada@shogokatsurada
    Active Exploitation

    JFrog Artifactory の脆弱性3件が、実際に連鎖で使われています CVE-2026-42016 / 42018 / 82329 認証回避 → 管理者権限 → Rust製バックドア Wiz Research が in-the-wild で確認 CISA KEV にも入り始めています Artifactory は「アーティファクトの保管庫」なので、落ちるのはサーバ1台ではありません。信頼しているパッケージ全部 セルフホスト型でネットに接続している組織は、パッチか、公開面の遮断を先に https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-42018-cve-2026-82329

    Post summary

    Three CVEs in JFrog Artifactory are actively exploited in the wild, achieving authentication bypass, privilege escalation, and a Rust-based backdoor; organizations are urged to apply patches or block public-facing access.

    20010339
    834 followersView on X
  • Hardik Dagha@HardikDagha

    ack. Attackers chain CVE-2026-42018 (anonymous token leak) with CVE-2026-42016 (swap low-priv for admin scope), mint admin in under 5 min, then drop plugins and backdoors. CISA KEV due: Sep 25. Cloud is fixed. On-prem is on you.

    2000053
    10 followersView on X
  • Vikram Dias@BigVikDada
    Active Exploitation

    JFrog shipped the Artifactory fixes weeks ago. Attackers kept walking into self-hosted instances anyway. Three bugs. All patched. All in use. CVE-2026-42018, patched 12 Aug, hands an internal anonymous-user token to a caller who never logged in, even when anonymous access is off. CVE-2026-42016, patched 27 Jul, does not check token scope, so that low-privilege token becomes admin. CVE-2026-82329, patched 28 Aug, is a 9.8 auth bypass on the default config. No second bug required. Wiz watched the first two chained from 15 Aug through 8 Sep. The third ran on its own from 1–8 Sep. After admin: new admin accounts, Groovy plugins, web shells, minted tokens, stolen cluster keys, SSH keys glued onto created users, and a custom Rust backdoor that survives the upgrade if you only patch. Wiz’s scan numbers are the part I would put on the slide. Six weeks after 42016 shipped, 59 percent of instances still open. Four weeks after 42018, 62 percent. Two weeks after the critical bypass, 49 percent. CISA put 82329 on KEV first, then 42018 and 42016. BOD 26-04 clock for federal systems is two weeks from listing. JFrog cloud is out of scope. Self-hosted is the problem. Fixed builds Wiz and SecurityWeek are pointing teams at: 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, 7.111.21. Confirm your branch against the JFrog advisory before you treat the ticket closed. What I would take into the room: 1. Pull every self-hosted Artifactory version tonight. If it is not on the fixed build for that branch, isolate it from the internet and patch. 2. Hunt from 15 Aug: unexpected admin users, Groovy plugins, new SSH keys on service accounts, minted tokens, cluster-key reads. 3. Rotate Artifactory tokens, repo credentials, and anything that instance could mint. Do not assume the Rust implant left when the version number changed. 4. Ask the owner one question: which CI jobs still pull from an internet-reachable Artifactory. That is the operational lesson, not the headline. The registry your pipeline trusts is the persistence layer. Source: Wiz, “Artifactory Under Attack,” 10 Sep 2026. Register write-up 11 Sep. CISA KEV listings follow. #Artifactory #KEV #supplychain

    Post summary

    The text reports active exploitation of three self-hosted JFrog Artifactory vulnerabilities, including observed chained attacks and CISA KEV listings. It also provides remediation guidance, fixed versions, and technical descriptions of the flaws.

    10010104
    160 followersView on X
  • Anurag Verma@anurag_629
    Active Exploitation

    Three chained bugs in @jfrog Artifactory add up to unauthenticated admin access, confirmed under active exploitation by Wiz (https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html). CVE-2026-82329 (CVSS 9.8) forges a cluster-join key straight into admin. The other two, CVE-2026-42016 and CVE-2026-42018, chain two POST requests into the same result even with anonymous access turned off. CISA has given federal agencies until September 25 to patch the newest pair. If Artifactory's exposed to the internet, that's not a someday-patch.

    Post summary

    The tweet reports three chained Artifactory bugs, with CVE‑2026‑82329 (CVSS 9.8) granting unauthenticated admin access and confirmed under active exploitation, and CISA urging agencies to patch by September 25.

    00020110
    315 followersView on X
  • multilayer@multilayer

    Cloudflareが、9/25のWAF Emergencyリリースを出した。 WordPressのパス辿り/ローカルファイル読み取り(CVE-2026-87902)と、JFrog Artifactoryの認証回避(CVE-2026-42018/CVE-2026-82329)向けに、Managed Rulesetの新しい検知をBlockで入れた。オリジン側はベンダーパッチが本命で、WAFは手前の守り、との位置づけ。 パッチを当てるまでの隙間を、エッジで塞げるのがうれしい。WordPressやArtifactoryを外に出しているなら、ルールが入ったかだけでも先に確認したほうがいいかも。 #Cloudflare #WAF #セキュリティ https://developers.cloudflare.com/changelog/post/2026-09-25-emergency-waf-release/

    00010105
    800 followersView on X
  • Jim Nitterauer@JNitterauer
    Active Exploitation

    Attackers chain three JFrog Artifactory flaws to seize admin control and plant Rust backdoors — Wiz and watchTowr confirmed in-the-wild exploitation of CVE-2026-42016, CVE-2026-42018 and… #CyberSecurity #InfoSec https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/

    Post summary

    The text reports confirmed in-the-wild exploitation of three chained JFrog Artifactory vulnerabilities, used by attackers to seize admin control and deploy Rust backdoors, as verified by Wiz and watchTowr.

    00100186
    8.5K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    JFrog Artifactory の脆弱性 CVE-2026-42018/42016/82329:積極的な悪用と Admin 権限奪取 https://iototsecnews.jp/2026/09/11/jfrog-artifactory-vulnerabilities-actively-exploited-in-the-wild-to-gain-administrative-control/ JFrog Artifactory の複数の深刻な脆弱性 CVE-2026-42018/CVE-2026-42016/CVE-2026-82329 に関する記事が紹介されています。これらは実環境において積極的に悪用されており、認証回避/権限昇格/管理者権限の奪取を引き起こします。その結果、開発環境への侵入やバックドアの設置といった重大な被害が生じるリスクがあります。影響を受ける環境では、最新バージョンへの更新/外部公開されている端末の特定/不審なアクセスログの調査など、適切な対応が強く求められます。 #Artifactory #CVE202642016 #CVE202642018 #CVE202682329 #Exploit #JFrog #Vulnerability

    Post summary

    The tweet highlights multiple JFrog Artifactory CVEs that are actively exploited in the wild to achieve administrative control, emphasizing the need for immediate updates and incident response.

    10000114
    515 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjfrogartifactory---

Explore more