Artifactory Vulnerabilities Exploited to Escalate Privileges and Deploy Backdoor on Servers

Views: 51 views

503/69 Monday, September 14, 2026

Reports indicate that attackers are exploiting Critical and High-severity vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges to administrator level, and install Rust-based backdoor malware on vulnerable self-hosted servers. A report from cloud security company Wiz confirmed observed attacks, including the chaining of CVE-2026-42018 and CVE-2026-42016 to access systems and escalate privileges. Another vulnerability, CVE-2026-82329, is a Critical authentication bypass flaw that watchTowr previously observed being exploited to create unauthorized administrator tokens.

According to Wiz, attackers used CVE-2026-42018 to obtain a JSON Web Token (JWT) belonging to Artifactory’s internal anonymous user, even when anonymous access had been disabled. They then exploited CVE-2026-42016, which stems from insufficient token validation, to escalate from low-level privileges to administrator access. After gaining system access, attackers could steal large volumes of data and install a backdoor on the compromised server. The report also stated that ShinyHunters moved quickly after gaining initial access. In one case involving an enterprise software company, the attackers stole a large amount of data within only a few hours. In another case, they progressed from a single stolen developer token to administrator-level control in less than three hours.

The report also discussed the use of AI in cyberattack activities by various threat groups. Anthropic stated that it observed Midnight Blizzard using Claude to assist with multiple stages of activity, including malware development, phishing infrastructure provisioning, command-and-control (C2) persistence, and data theft. It also identified activity by a Chinese-language group tracked as GTG-10007, which used Claude as part of vulnerability research, exploit development, malware development, and the creation of an intelligence-gathering platform. The group targeted around 50 organizations across multiple sectors, including government, education, energy, technology, healthcare, finance, and manufacturing. Anthropic stated that it suspended the related accounts, strengthened safeguards against misuse, and coordinated with relevant organizations.

Source: https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/