MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-11 · via BleepingComputer

Critical Artifactory vulnerabilities exploited to install Rust backdoor

Image via BleepingComputer
Image via BleepingComputer

Threat actors have been exploiting multiple vulnerabilities in JFrog Artifactory to bypass authentication and gain admin access. The chain combines CVE-2026-42018 and CVE-2026-42016, allowing attackers to mint admin tokens and deploy a Rust-based backdoor. Wiz reports that between 49% and 62% of reachable instances are vulnerable, and urges immediate upgrades.

Expanded Detail

The exploit chain leverages a low-privilege token from an internal anonymous user, even when anonymous access is disabled, then escalates it via flawed token validation. Attackers reportedly created administrator accounts in under five minutes.

Post-compromise actions included installing malicious Groovy plugins, dropping a Rust-based backdoor with command-and-control capabilities, and exfiltrating configuration data and cluster join keys. Wiz advises immediate upgrades to specific patched versions and checking for rogue accounts or suspicious plugin activity.

Context

The widespread exposure of Artifactory instances means organizations relying on self-hosted software repositories could face severe supply-chain risks. If attackers gain admin access, they may tamper with artifacts or steal credentials, potentially compromising downstream software builds. This could lead to broader data breaches or malware distribution across an enterprise's ecosystem. Immediate patching and forensic review are likely essential to mitigate these threats, though the high percentage of vulnerable instances suggests many organizations may remain exposed for some time.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
SAP Patches Critical Kernel Flaw Allowing Remote Code Execution · Cybersecurity
Active exploitation of MikroTik RouterOS vulnerabilities allows full router takeover · Cybersecurity
Cisco warns of active exploitation of critical firewall management flaw · Cybersecurity
Cisco firewall management flaws exploited by multiple threat groups · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Artifactory flaws chained in attacks deploying backdoor malware.” Browse more stories.