<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert-fl2nmmecb" -->

---
title: Exploited JFrog Artifactory bug puts software supply...
description: A critical authentication bypass in JFrog Artifactory, tracked as CVE-2026-82329 (CVSS 9.8), is being actively exploited in the wild. Disclosed by JFrog on...
canonical: https://daily.dev/posts/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert-fl2nmmecb
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Exploited JFrog Artifactory bug puts software supply chain on alert | daily.dev
og:description: A critical authentication bypass in JFrog Artifactory, tracked as CVE-2026-82329 (CVSS 9.8), is being actively exploited in the wild. Disclosed by JFrog on...
og:url: https://daily.dev/posts/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert-fl2nmmecb
og:image: https://api.daily.dev/og/posts/fl2nmMeCb.png
og:image:alt: Exploited JFrog Artifactory bug puts software supply chain on alert
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Exploited JFrog Artifactory bug puts software supply chain on alert

**[CSO Online](https://daily.dev/sources/csoonline)** · 3 min read · 2 upvotes · 0 comments

## Summary

A critical authentication bypass in JFrog Artifactory, tracked as CVE-2026-82329 (CVSS 9.8), is being actively exploited in the wild. Disclosed by JFrog on August 28, the flaw allows unauthenticated attackers with network access to obtain administrator privileges via a 'phantom' join key issued to instances lacking an additional configured join key. watchTowr observed attackers minting admin tokens and enumerating users, groups, credentials, and federated access topologies as early as September 1. JFrog has released patched versions (7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20) for self-hosted deployments, and cloud environments have been fortified. Experts warn that patching alone does not revoke tokens minted before remediation, and recommend rotating admin tokens, inspecting audit logs, and verifying artifact signatures at deployment time rather than trusting stored signatures.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4217534/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert.html>

## Questions this post answers

### What is CVE-2026-82329 in JFrog Artifactory and how does it work?

CVE-2026-82329 is a critical authentication bypass (CVSS 9.8) in JFrog Access, the component that issues and validates credentials in Artifactory. Instances without an additional join key configured receive a default 'phantom' join key that unauthenticated attackers with network access can abuse to forge access and mint administrator-level credentials, disclosed by JFrog on August 28.

_Track actively exploited CVEs like this one in your supply chain stack on daily.dev._

### Which Artifactory versions fix CVE-2026-82329?

JFrog released patched self-hosted versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20, depending on the release branch in use. Cloud-hosted Artifactory environments were already fortified by JFrog and do not require separate patching by customers.

_Developers rolling out artifact-repository patches keep version details straight on daily.dev._

### If I patch Artifactory for CVE-2026-82329, is my instance fully secure again?

No, patching alone does not remove access an attacker may have already gained. Administrator tokens minted before remediation can remain valid until explicitly revoked, so organizations should revoke and reissue admin tokens, inspect audit logs, rotate exposed credentials, and investigate connected systems for backdoors or malicious changes on any instance that was exposed while vulnerable.

_Teams responding to supply-chain incidents like this compare remediation steps on daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication)

[View this post on daily.dev](https://daily.dev/posts/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert-fl2nmmecb)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Exploited JFrog Artifactory bug puts software supply chain on alert","url":"https://daily.dev/posts/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert-fl2nmmecb","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert-fl2nmmecb"},"datePublished":"2026-09-02T12:25:44.834Z","dateModified":"2026-09-02T12:55:40.437Z","description":"A critical authentication bypass in JFrog Artifactory, tracked as CVE-2026-82329 (CVSS 9.8), is being actively exploited in the wild. Disclosed by JFrog on...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cf21a84017133eca96a02ebe1bbba598?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cf21a84017133eca96a02ebe1bbba598?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert-fl2nmmecb","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,authentication","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Exploited JFrog Artifactory bug puts software supply chain on alert"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert-fl2nmmecb#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-82329 in JFrog Artifactory and how does it work?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-82329 is a critical authentication bypass (CVSS 9.8) in JFrog Access, the component that issues and validates credentials in Artifactory. Instances without an additional join key configured receive a default 'phantom' join key that unauthenticated attackers with network access can abuse to forge access and mint administrator-level credentials, disclosed by JFrog on August 28. Track actively exploited CVEs like this one in your supply chain stack on daily.dev."}},{"@type":"Question","name":"Which Artifactory versions fix CVE-2026-82329?","acceptedAnswer":{"@type":"Answer","text":"JFrog released patched self-hosted versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20, depending on the release branch in use. Cloud-hosted Artifactory environments were already fortified by JFrog and do not require separate patching by customers. Developers rolling out artifact-repository patches keep version details straight on daily.dev."}},{"@type":"Question","name":"If I patch Artifactory for CVE-2026-82329, is my instance fully secure again?","acceptedAnswer":{"@type":"Answer","text":"No, patching alone does not remove access an attacker may have already gained. Administrator tokens minted before remediation can remain valid until explicitly revoked, so organizations should revoke and reissue admin tokens, inspect audit logs, rotate exposed credentials, and investigate connected systems for backdoors or malicious changes on any instance that was exposed while vulnerable. Teams responding to supply-chain incidents like this compare remediation steps on daily.dev."}}]}
```

