JFrog security advisory (AV26-867) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-867 Date: September 1, 2026 Updated: September 2, 2026 As of August 28, 2026, JFrog is affected by a vulnerability in the following product: Artifactory Prior to 7.111.21 Prior to 7.117.28 Prior to 7.125.20 Prior to 7.133.29 Prior to 7.146.38 Prior to 7.161.20 Open-source reporting indicates that CVE-2026-82329 related to JFrog Artifactory is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-82329 to their Known Exploited Vulnerabilities (KEV) Database. Artifactory Self-Managed Releases JFrog Security Advisories CISA KEV: CVE-2026-82329
CSIRTS triage
- What
- CVE-2026-82329 is a vulnerability affecting JFrog Artifactory that is currently being exploited in the wild.
- Who is affected
- Deployments of JFrog Artifactory Self-Managed running versions before the specified patch releases are affected.
- Urgency
- High urgency due to active exploitation in the wild as of August 28, 2026.
- Action
- Update to the patched versions immediately: 7.111.21 or later, 7.117.28 or later, 7.125.20 or later, 7.133.29 or later, 7.146.38 or later, or 7.161.20 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Artifactory
Get an email when a new Artifactory advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/jfrog-security-advisory-av26-867
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-82329Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 67% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-82329 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploited[NEW] [high] JFrog Artifactory: Vulnerability allows obtaining administrator privilegescert-bund
- highexploitedCISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa
- unknownexploitedNCSC-2026-0336 [1.00] [M/H] Vulnerability patched in JFrog Artifactoryncsc-nl
- criticalexploitedCVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerabilitycisa-kev
- unknownexploitedMultiple vulnerabilities in JFrog Artifactory (September 01, 2026)cert-fr-avis
- criticalexploitedCVE-2026-82329: JFrog Artifactory contains an authentication weakness that, under default configuration, may a…nvd
More from Canadian Centre for Cyber Security
- unknownSonicWall security advisory (AV26-872) – Update 12026-09-02
- unknownProgress Software security advisory (AV26-875)2026-09-02
- unknownGoogle security advisory (AV26-874)2026-09-02
- unknownHPE security advisory (AV26-873)2026-09-02
- unknown[Control systems] Schneider Electric security advisory (AV26-871)2026-09-02