CISOOnline

Exploited JFrog Artifactory bug puts software supply chain on alert

The vulnerability was assigned a critical severity (CVSS 9.8)  and affects several self-hosted Artifactory release branches. JFrog has released fixes for affected self-hosted versions, while affected cloud environments have already been fortified.

Users are advised to upgrade to versions 7.111.21,7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20, depending on their release branch.

“Admin on Artifactory means admin on its own checks,” said Collin Hogue-Spears, senior director of Solution Management at Black Duck. “CVE-2026-82329 delivers an intrusion. Administrative control of the repository turns that intrusion into a substitution.”



Source link