JFrog Artifactory CVE-2026-42016: token scope privilege escalation (chained in wild)
Wiz Research (10 September 2026) says CVE-2026-42016 is a privilege-escalation flaw from insufficient token scope enforcement: Artifactory validates signature/issuer but not intended scope, so a low-privileged token (including the anonymous token from CVE-2026-42018) can be escalated. Wiz observed the 42018→42016 chain in the wild 15 August–8 September 2026 alongside separate abuse of CVE-2026-82329; post-exploitation included persistent admin users, malicious Groovy plugins, and Rust C2 backdoors. Wiz lists CVE-2026-42016 impacted prior to 7.133.11 with remediated 7.133.11; for the overall campaign they urge upgrading to 7.111.21 / 7.117.28 / 7.125.20 / 7.133.29 / 7.146.38 / 7.161.20 or later and reviewing auth/admin activity. Primary: Wiz; vendor: JFrog advisories. UPDATE 11 September 2026: CISA added CVE-2026-42016 to the Known Exploited Vulnerabilities catalog (dateAdded 2026-09-11; catalogVersion 2026.09.11). Prioritise patching self-hosted Artifactory under BOD 26-04-style exploited-first triage; hunt anonymous/admin tokens, Groovy plugins, and Rust C2 per Wiz.
- Product
- JFrog Artifactory (self-hosted)
- Versions
- Impacted per Wiz: prior to 7.133.11; remediated 7.133.11 (also apply latest train patches covering the wider chain)
- Exploited in Australia?
- unknown
- Patch to
- Upgrade to fixed Artifactory builds; revoke suspicious tokens; hunt Groovy plugin and Rust backdoor IoCs per Wiz
Primary: Wiz — Artifactory under attack (10 Sep 2026) · Vendor: JFrog security advisories · CVE: CVE-2026-42016, CVE-2026-42018, CVE-2026-82329 · The Hacker News (11 Sep 2026)
