Three security flaws in Artifactory are under active exploitation, allowing attackers to bypass authentication on Internet-facing, self-hosted Artifactory deployments and potentially establish persistent administrator access in under five minutes, according to a disclosure published by security firm Wiz.io. The vulnerabilities can be chained together to enable dangerous post-authentication activity, including credential and key theft, arbitrary code execution, persistence, and anti-forensics measures. Because Artifactory sits at the center of many software supply chains, the flaws pose a direct supply-chain risk that security experts are comparing to the SolarWinds incident.
The three vulnerabilities are CVE-2026-42018, rated high severity, which can cause Artifactory to return an internal anonymous-user token to an unauthenticated requester even when anonymous access is disabled; CVE-2026-42016, also rated high severity, which causes Artifactory to fail to properly validate a request's token so an attacker with low-privileged access can use a valid token to perform unauthorized actions and gain elevated privileges; and CVE-2026-82329, rated critical severity, which allows an unauthenticated attacker to obtain administrative control. Two of the vulnerabilities can be chained in an attack leading to persistent admin accounts and further post-exploitation. Every exploitation followed a similar shape: an unauthenticated POST request with a trailing slash returned a JWT for the internal anonymous user, exploiting CVE-2026-42018, then the actor exchanged that JWT for an admin-scoped token through another POST request, exploiting the CVE-2026-42016 scope-validation flaw. The escalated token kept the anonymous username but carried admin authority. Once administrative access is obtained, attackers have been observed creating persistent administrator accounts, deploying malicious Groovy plugins for code execution, harvesting credentials and Access signing keys, establishing backdoors, and deploying anti-forensics mechanisms.
According to Wiz.io, "these CVEs are trivial to exploit, a handful of unauthenticated HTTP requests," and the firm warns that if an instance was exposed while vulnerable, organizations should assume compromise and hunt for post-exploitation artifacts, because "upgrading closes the door but does not evict an attacker who is already inside." Cybersecurity specialist Erik York commented that Artifactory sits at the center of many software supply chains and "this is exactly the kind of bug that turns into next year's SolarWinds story if it's not patched fast." Jim Nitterauer, senior director of information security at Graylog, stressed the importance of patching all affected systems to keep supply chains safe, noting that patch adoption has lagged badly, with attacks observed within four days of disclosure of the third bug.
All Artifactory self-hosted environments should be immediately patched to any version fixing the vulnerabilities, including 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20, or newer depending on the deployed release branch. The report emphasizes that upgrading alone doesn't remove an attacker who has already established access, so organizations must actively search for signs of compromise even after applying patches. In some observed cases, attackers completed the exploitation and established administrative access in under five minutes, leaving a narrow window for detection before full compromise. Organizations operating continuous integration and delivery pipelines face heightened urgency, since artifact repositories anchor nearly every phase of modern software development and distribution.

