TL;DR

what: Attackers chained CVE-2026-42018 and CVE-2026-42016 in self-hosted JFrog Artifactory to turn an unauthenticated request into an administrator-scope token, then installed Groovy plugins and Rust backdoors.

impact: Compromised servers gave up administrator accounts, code execution, command-and-control channels, and in several cases the cluster join key that Artifactory nodes use to register with one another.

fix: Upgrade to the fixed build for your branch (7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20 covers CVE-2026-82329; 7.133.11 covers CVE-2026-42016), then rotate the join key and revoke tokens issued since August 28.

who: Anyone running self-hosted Artifactory on an unpatched build, especially internet-facing instances; JFrog says cloud instances need no action.