Attackers reportedly exploit a critical authentication-bypass flaw in JFrog Artifactory shortly after it is publicly disclosed. Multiple reports say exploitation begins only days after the vulnerability is made public, indicating fast-moving threat activity.
The issue is identified as CVE-2026-82329, described as having a very high severity score (CVSS 9.8). The flaw is characterized as an authentication bypass that can allow access that effectively reaches administrative capabilities in Artifactory. One outlet cites reporting from watchTowr, while another notes that the exploitation starts just days after the vulnerability’s disclosure.
While the outlets align on the existence of the vulnerability, its general impact, and the timing of in-the-wild activity, they provide limited additional operational detail. Both accounts focus on the urgency of the reported exploitation and imply that defenders should treat the flaw as actively targeted soon after disclosure, even though specifics on the attackers’ methods and scale are not fully detailed in the provided excerpts.