JFrog has released security updates addressing CVE-2026-82329. Users should apply the latest Artifactory version containing the fix immediately. It is also recommended to review and restrict access controls, monitor for suspicious activity in CI/CD pipelines, and consult JFrog's official security bulletin for exact patch versions and mitigation steps.
Quick answers
What is CVE-2026-82329?
JFrog has released security updates addressing CVE-2026-82329. Users should apply the latest Artifactory version containing the fix immediately. It is also recommended to review and restrict access controls, monitor for suspicious activity in CI/CD pipelines, and consult JFrog's official security bulletin for exact patch versions and mitigation steps.
How severe is CVE-2026-82329?
critical
Is CVE-2026-82329 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-82329 be mitigated?
JFrog has released security updates addressing CVE-2026-82329. Users should apply the latest Artifactory version containing the fix immediately. It is also recommended to review and restrict access controls, monitor for suspicious activity in CI/CD pipelines, and consult JFrog's official security bulletin for exact patch versions and mitigation steps.
CVSS
—
Vendor
JFrog
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Artifactory
Mitigation
JFrog has released security updates addressing CVE-2026-82329. Users should apply the latest Artifactory version containing the fix immediately. It is also recommended to review and restrict access controls, monitor for suspicious activity in CI/CD pipelines, and consult JFrog's official security bulletin for exact patch versions and mitigation steps.
The Cybersecurity and Infrastructure Security Agency (CISA) has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild. The additions span multiple vendors and technologies, including Sangoma Switchvox, Kludex Starlette, Kestra OSS, LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances. CISA emphasized that these flaws represent frequent attack vectors for malicious actors targeting federal and critical infrastructure systems.
A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, has been disclosed and is being actively exploited in the wild. The flaw allows threat actors to gain administrator-level access without valid credentials, potentially enabling supply chain compromise and artifact tampering.