Critical Artifactory vulnerabilities exploited to install Rust backdoor

Threat actors have been exploiting multiple vulnerabilities in JFrog Artifactory to bypass authentication and gain admin access. The chain combines CVE-2026-42018 and CVE-2026-42016, allowing attackers to mint admin tokens and deploy a Rust-based backdoor. Wiz reports that between 49% and 62% of reachable instances are vulnerable, and urges immediate upgrades.
The exploit chain leverages a low-privilege token from an internal anonymous user, even when anonymous access is disabled, then escalates it via flawed token validation. Attackers reportedly created administrator accounts in under five minutes.
Post-compromise actions included installing malicious Groovy plugins, dropping a Rust-based backdoor with command-and-control capabilities, and exfiltrating configuration data and cluster join keys. Wiz advises immediate upgrades to specific patched versions and checking for rogue accounts or suspicious plugin activity.
The widespread exposure of Artifactory instances means organizations relying on self-hosted software repositories could face severe supply-chain risks. If attackers gain admin access, they may tamper with artifacts or steal credentials, potentially compromising downstream software builds. This could lead to broader data breaches or malware distribution across an enterprise's ecosystem. Immediate patching and forensic review are likely essential to mitigate these threats, though the high percentage of vulnerable instances suggests many organizations may remain exposed for some time.