Skip to main content
Security

Attackers exploit Artifactory authentication-bypass flaw

Attackers exploit Artifactory authentication-bypass flaw Image: Primary
Threat actors began exploiting CVE-2026-82329 in JFrog Artifactory on September 1, according to watchTowr. The critical authentication-bypass flaw can allow an unauthenticated network attacker to obtain administrative privileges under default configuration. WatchTowr said exploitation has included minting administrator tokens and enumerating users, groups, credential sets and federated-access topologies. JFrog released Artifactory 7.161.20 on August 28 to patch the issue; several prior release ranges are affected.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

SonicWall reports exploited SMA1000 zero-days and releases fixes

SecurityWeek reported that SonicWall urged SMA1000 customers to patch two zero-day vulnerabilities the vendor says have been exploited. CVE-2026-83548 is a pre-authentication SSRF flaw in the Appliance Work Place interface that ca...

Security AI
Security AI

Langflow flaw is being exploited to harvest cloud and AI credentials

Threat actors are exploiting CVE-2026-0768, an unauthenticated remote-code-execution flaw in Langflow's custom-component code validator, to steal credentials, tokens and keys, according to VulnCheck observations reported by Bleepi...

AI Security
AI Security

OpenAI says Astra reached its critical cyber-capability threshold

OpenAI says its forthcoming Astra model has reached the company's threshold for critical cyber capabilities, defined as independently finding and exploiting previously unknown vulnerabilities in real-world software. The company p...