A critical authentication vulnerability in JFrog Artifactory was exploited on the same day its CVE was published, leaving no patch window for users. The flaw allows unauthenticated attackers to gain administrative privileges.

A critical authentication bypass vulnerability in JFrog Artifactory, identified as CVE-2026-82329, was exploited by threat actors on the same day it was publicly disclosed. The flaw, which carries a CVSS score of 9.8, allows an unauthenticated attacker with network access to gain administrative privileges on affected systems under default configurations.
The vulnerability was published on August 28, 2026, and was immediately added to commercial research vulnerability catalogs, with the first public exploitation evidence also reported on that date. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the European Union Agency for Cybersecurity (ENISA) subsequently added it to their respective Known Exploited Vulnerabilities (KEV) catalogs on September 2, 2026.
Multiple public reports of exploitation emerged shortly after disclosure, with several sources indicating active attacks by September 1, 2026. These reports confirm that attackers quickly moved to leverage the vulnerability to obtain administrator-level access.
JFrog Artifactory is a widely used universal repository manager. The vendor has released security advisories and self-managed release documentation detailing mitigations for the flaw. CISA has issued a directive requiring federal agencies to apply these mitigations by September 5, 2026, in accordance with their Binding Operational Directive 26-04, which prioritizes security updates based on risk. For cloud services or situations where mitigations are unavailable, CISA advises discontinuing product use.
The rapid exploitation of CVE-2026-82329 highlights the critical need for organizations to promptly apply security updates, especially for vulnerabilities that are publicly disclosed and immediately confirmed to be under active attack. The vulnerability's presence in multiple KEV catalogs underscores its severe risk and the urgency of patching.

CVE-2026-81578, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

CVE-2026-82078, a critical vulnerability in PaperCut NG/MF, was reported as exploited on or before its official publication date, leaving no patch window for users.

A critical OS command injection vulnerability in SonicWall SMA1000 Appliances was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

A critical pre-authentication SSRF vulnerability in SonicWall SMA1000 appliances was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.