TTO-2026-0911-118 · September 11, 2026 Active ExploitationSupply ChainFollow-Up

Two New CVEs Chained With Prior JFrog Artifactory Flaw to Deploy Rust Backdoor — Updates TTO-2026-0903-097

jfrog.comCVE-2026-42018 + CVE-2026-42016 chainCVE-2026-82329 CVSS 9.8Rust backdoorWiz confirmed Aug 15-Sep 8Updates TTO-2026-0903-097

Summary

Cloud security company Wiz has confirmed that between August 15 and September 8, 2026, multiple threat actors chained two newly identified JFrog Artifactory vulnerabilities — CVE-2026-42018 and CVE-2026-42016 — to obtain administrative access to self-hosted Artifactory servers and deploy a Rust-based backdoor. CVE-2026-82329, covered in TTO-2026-0903-097, was observed exploited separately as a standalone authentication bypass during the same period. All three vulnerabilities are now confirmed exploited in the wild. JFrog had patched all three before the exploitation window began; only unpatched servers are at risk.

Timeline

DateEvent
Sep 1, 2026Public exploit for CVE-2026-82329 appears; Fastly observes 406,000 exploitation attempts on September 2
Sep 3, 2026TTO-2026-0903-097 published covering CVE-2026-82329 exploitation and administrator token forgery
Aug 15 - Sep 8, 2026Wiz observes multiple actors chaining CVE-2026-42018 + CVE-2026-42016 to gain admin access and deploy Rust backdoor
Sep 11, 2026Wiz publishes full analysis; three distinct exploitation patterns confirmed across multiple environments

What Happened

CVE-2026-42018 allows an unauthenticated attacker to obtain a JSON Web Token belonging to Artifactory's internal anonymous user, even when anonymous access is disabled. CVE-2026-42016, caused by insufficient token validation, allows the attacker to exchange that low-privilege anonymous token for one with full administrator scope. In cases Wiz documented, attackers completed the chain in under five minutes. Administrator actions taken using the exchanged token appear in Artifactory logs as token:anonymous rather than under a named account, reducing visibility.

After gaining administrator access, attackers installed malicious Groovy plugins via Artifactory's plugin framework to execute arbitrary commands, created long-lived administrator access tokens for persistence, and deployed a Rust-based backdoor that retrieved additional binaries over plain HTTP, wrote them to world-writable directories such as /tmp, and opened a command-and-control channel. CVE-2026-82329, the standalone CVSS 9.8 bypass from the prior bulletin, was exploited separately during the same period to steal cluster join keys and system configuration data. All three vulnerabilities are patched; unpatched self-hosted Artifactory instances remain at risk.

Domain Intelligence

jfrog.com — 61.99

Score unchanged from TTO-2026-0903-097. JFrog is the vendor that patched all three vulnerabilities before the exploitation window began. The score reflects jfrog.com's domain trust posture independently of the severity of the vulnerabilities in its product.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 11, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026