Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek.

Reports indicate that a critical authentication bypass vulnerability affecting JFrog Artifactory, identified as CVE-2026-82329, is actively being exploited in the wild. This exploitation reportedly began mere days following the public disclosure of the flaw.
The vulnerability, an authentication bypass, allows an attacker to circumvent security mechanisms designed to verify user identity. In the context of JFrog Artifactory, a universal repository manager, such a bypass could grant unauthorized access to sensitive artifacts, build information, and configuration settings. The specific technical mechanism of this bypass has not been detailed, but authentication bypasses often involve flaws in session management, token validation, or the processing of authentication requests that allow an attacker to assume a privileged identity or bypass the authentication gate entirely.
JFrog Artifactory is a widely used platform in software development and DevOps pipelines, serving as a central hub for managing binary artifacts throughout their lifecycle. It supports various package types, including Docker images, Maven, npm, and NuGet, making it a critical component in many organizations' software supply chains. The compromise of an Artifactory instance could have far-reaching implications, potentially enabling attackers to inject malicious code into software builds, exfiltrate proprietary source code, or disrupt development operations.
The rapid transition from public disclosure to observed exploitation highlights the urgency for organizations to address this vulnerability. This pattern is common with critical flaws in widely deployed enterprise software, where threat actors quickly weaponize publicly available proof-of-concept exploits or reverse-engineer patches to develop their own attack tools.
Mitigation for authentication bypass vulnerabilities typically involves applying vendor-supplied patches immediately. Organizations using JFrog Artifactory should prioritize updating their instances to a version that addresses CVE-2026-82329. Additionally, implementing strong network segmentation, monitoring Artifactory access logs for unusual activity, and enforcing multi-factor authentication where possible are general best practices that can help reduce the impact of such vulnerabilities.
The reported exploitation of CVE-2026-82329 underscores the persistent challenge of securing critical infrastructure components within the software supply chain. The speed with which this vulnerability moved from disclosure to active exploitation serves as a stark reminder of the need for rapid patching cycles and robust vulnerability management programs, particularly for systems that are central to an organization's development and deployment processes.

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs