← nejvýznamnější zprávy

SPOJENO AI KEV ✓ EPSS 0.11

Artifactory flaws chained in attacks deploying backdoor malware

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]

5 zpráv z 4 zdrojů · první 2. 9. 10:32 · poslední 14. 9. 11:15 CZ · EN/orig

JFrog IT US NL

tg: varování tg: zneužíváno tg: zranitelnost tp: malware tp: identita

CVE v události 2

CVEhodnoceníKEVEPSS
CVE-2026-42016 8.1 3.1 · JFROG KEV ✓ 0.09
CVE-2026-42018 7.5 3.1 · JFROG KEV ✓ 0.11

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Dalších 1 CVE zmiňuje jen text zpravodajského článku (CVE-2026-82329). Nejsou to identifikátory téhle události, proto nejsou v tabulce ani v odznacích.

Jak se o tom psalo 5

  1. · CSIRT Itálie (ACN) IT

    JFrog: rilevato sfruttamento in rete delle vulnerabilità CVE-2026-42016 e CVE-2026-42018 in Artifactory

    Rilevato lo sfruttamento attivo in rete di due vulnerabilità con gravità "alta" - già sanate dal vendor - relative al prodotto JFrog Artifactory, piattaforma per la gestione e distribuzione di artefatti software

  2. · BleepingComputer US nadpis události

    Artifactory flaws chained in attacks deploying backdoor malware

    Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]

  3. · CISA KEV US

    JFrog Artifactory Improper Authentication Vulnerability (CVE-2026-42018)

    CISA added CVE-2026-42018 to the Known Exploited Vulnerabilities catalog. Affected product: JFrog Artifactory. Remediation due date: 2026-09-25.

  4. · CISA KEV US

    JFrog Artifactory Incorrect Authorization Vulnerability (CVE-2026-42016)

    CISA added CVE-2026-42016 to the Known Exploited Vulnerabilities catalog. Affected product: JFrog Artifactory. Remediation due date: 2026-09-25.

  5. · NCSC-NL NL

    NCSC-2026-0336 [1.00] [M/H] Kwetsbaarheid verholpen in JFrog Artifactory

    JFrog heeft een kwetsbaarheid verholpen in JFrog Artifactory. De kwetsbaarheid bevindt zich in de standaardconfiguratie van JFrog Artifactory, waarbij onvoldoende authenticatiecontroles aanwezig zijn. Hierdoor kan een niet-geauthenticeerde aanvaller met netwerktoegang de privileges escaleren naar administratief niveau. Dit kan leiden tot volledige administratieve controle over het systeem.