Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Cybersecurity · September 13, 2026

Cybersecurity·thehackernews.com

Security researchers at Wiz found that attackers chained two vulnerabilities in JFrog Artifactory to seize administrator control of self-hosted instances that had not applied JFrog's fixes. The intrusions ran from mid-August through early September, and once inside, the attackers planted backdoors — BleepingComputer separately reported a Rust-based backdoor turning up on compromised servers. Teams running self-managed Artifactory deployments should verify both flaws are patched.

// source: thehackernews.com ↗

Back to Blog