AI Weekly Malaysia

Back to items Summaries

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

ID
23461
Status
summarized
Published
11 Sep 2026, 3:31 PM
Fetched
11 Sep 2026, 4:09 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.0
Created
11 Sep 2026, 4:09 PM
Tags
Audience
developersvibe_coderssaas_founders

What happened

Wiz observed attackers chaining two patched JFrog Artifactory flaws (CVE-2026-42018 and CVE-2026-42016) on unpatched self-hosted servers between August 15 and September 8, 2026. The first flaw hands an internal anonymous-user token even when anonymous access is off; the second lets that token be swapped for admin scope, with admin actions logging as 'token:anonymous' — making detection harder. Attackers created persistent admin accounts, installed malicious Groovy plugins for code execution, and established C2 channels, sometimes going from zero to admin in under five minutes.

Why it matters

If your team runs self-hosted JFrog Artifactory, check immediately whether you are on a version patched for both CVE-2026-42018 and CVE-2026-42016 — the 7.133 branch was only fixed on August 12, 2026, and the 7.146 branch fix shipped April 28. Because admin actions from this chain appear as 'token:anonymous' in logs, search your Artifactory audit logs for that string and for unexpected Groovy plugins or admin accounts. Closing either CVE breaks the chain, so patching one is better than patching none while you schedule the other.

Discussion angle

How many Malaysian dev teams still run self-hosted Artifactory on delayed patch cycles, and what's a realistic patch SLA for build infrastructure when a single unpatched box can backdoor every artifact your pipeline pulls?

Top