SPOJENO AI KEV ✓ (2 z 2) EPSS 0.11 (nejvyšší)
Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]
JFrog IT US NL
CVE v události 2
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-42016 | 8.1 3.1 · JFROG | KEV ✓ | 0.09 |
| CVE-2026-42018 | 7.5 3.1 · JFROG | KEV ✓ | 0.11 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.
Tohle CVE jsem vytáhl z textu článku, ne ze seznamu chyb, který zpráva uvádí: CVE-2026-82329. Neukazuju u něj proto fakta z katalogů v tabulce výše. Ta najdete přímo na detailu toho CVE.
Jak se o tom psalo 5
-
· CSIRT Itálie (ACN) IT
JFrog: rilevato sfruttamento in rete delle vulnerabilità CVE-2026-42016 e CVE-2026-42018 in Artifactory
Rilevato lo sfruttamento attivo in rete di due vulnerabilità con gravità "alta" - già sanate dal vendor - relative al prodotto JFrog Artifactory, piattaforma per la gestione e distribuzione di artefatti software
-
· BleepingComputer US nadpis události
Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]
-
· CISA KEV US
JFrog Artifactory Improper Authentication Vulnerability (CVE-2026-42018)
CISA added CVE-2026-42018 to the Known Exploited Vulnerabilities catalog. Affected product: JFrog Artifactory. Remediation due date: 2026-09-25.
-
· CISA KEV US
JFrog Artifactory Incorrect Authorization Vulnerability (CVE-2026-42016)
CISA added CVE-2026-42016 to the Known Exploited Vulnerabilities catalog. Affected product: JFrog Artifactory. Remediation due date: 2026-09-25.
-
· NCSC-NL NL
NCSC-2026-0336 [1.00] [M/H] Kwetsbaarheid verholpen in JFrog Artifactory
JFrog heeft een kwetsbaarheid verholpen in JFrog Artifactory. De kwetsbaarheid bevindt zich in de standaardconfiguratie van JFrog Artifactory, waarbij onvoldoende authenticatiecontroles aanwezig zijn. Hierdoor kan een niet-geauthenticeerde aanvaller met netwerktoegang de privileges escaleren naar administratief niveau. Dit kan leiden tot volledige administratieve controle over het systeem.