Affected Systems
JFrog Artifactory self-managed instances in default configuration. Patched in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 (released August 28, 2026). JFrog Cloud environments already protected. All prior versions vulnerable.
Exploitation Status
Active exploitation confirmed. watchTowr researchers observed attackers forging admin tokens in the wild. No public PoC disclosed. Victim count and IoCs unknown.
Business Impact
Unauthenticated attackers with network access can mint administrative tokens and gain full control of Artifactory instances. Forged tokens persist after patching and must be manually revoked. Attackers can enumerate users, read artifacts, modify security configs, and poison trusted packages. High supply chain risk: compromised artifacts are automatically pulled by downstream build and deployment systems, enabling malicious code execution across the software delivery pipeline.
Urgency
🔴 Immediate
Recommended Actions
- Immediately upgrade self-managed JFrog Artifactory to patched versions: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20
- Revoke all existing access tokens in Artifactory after patching, as upgrade does not invalidate previously-issued tokens
- Audit Artifactory access logs for unauthorized token creation, user enumeration, and artifact modifications since vulnerability disclosure
- Review integrity of stored artifacts and compare checksums against known-good versions to detect potential poisoning
- Restrict network access to Artifactory instances to trusted IP ranges and enforce VPN or zero-trust access controls
