Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.

Attackers chained two JFrog Artifactory flaws on unupdated servers to gain admin control, while a third flaw was exploited separately.

TL;DR what: Attackers chained CVE-2026-42018 and CVE-2026-42016 in self-hosted JFrog...