High severity7.5CISA KEVNVD Advisory· Published Aug 12, 2026· Updated Sep 12, 2026
CVE-2026-42018
CVE-2026-42018
Description
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- docs.jfrog.com/releases/docs/jfrog-security-advisoriesnvdVendor Advisory
- www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201nvdThird Party Advisory
- docs.jfrog.com/releases/docs/artifactory-self-managed-releasesnvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
9- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and RootkitsThe Hacker News · Sep 14, 2026
- Three JFrog Artifactory Flaws Exploited for Backdoor DeploymentSecurityWeek · Sep 14, 2026
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVThe Hacker News · Sep 12, 2026
- More JFrog Artifactory bugs under attack, and all 3 have patchesThe Register Security · Sep 11, 2026
- JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative ControlCyber Security News · Sep 11, 2026
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant BackdoorsThe Hacker News · Sep 11, 2026
- Jfrog: 2 Actively-Exploited Flaws Added to CISA KEVVypr Intelligence · Sep 11, 2026
- JFrog Artifactory: 17 Vulnerabilities Disclosed, Highlighting Access Control and Metadata RisksVypr Intelligence · Aug 12, 2026
- CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA Alerts