Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
If you run self-hosted JFrog Artifactory, patch today. Attackers have been chaining token-disclosure and privilege-escalation bugs, plus a CVSS 9.8 auth bypass (CVE-2026-82329), to create backdoor admin accounts and install malicious plugins. Beyond upgrading: rotate join keys, revoke recent tokens, and audit admin users. Your artifact repo is your supply chain.