
Exploited JFrog Artifactory bug puts software supply chain on alert
A critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data.
The flaw, tracked as CVE-2026-82329, was disclosed by JFrog on August 28 and can, under default configuration, allow an unauthenticated attacker with network access to obtain administrative privileges.
By September 1, watchTowr said its Attacker Eye honeypot was already seeing threat actors exploit internet-exposed systems. The activity included attackers minting administrator tokens and enumerating users, groups, credential sets and federated access topologies.
“This moved from discl...