๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability
Summary
JFrog Artifactory has an improper authentication vulnerability (a flaw in how the software verifies user identity) that could accidentally give an internal anonymous-user token (a credential that grants access without logging in) to someone who shouldn't have access, especially when anonymous access is supposed to be turned off. This could expose sensitive files and data stored in Artifactory. This vulnerability is currently being exploited by attackers in real attacks.
Solution / Mitigation
Apply mitigations according to JFrog vendor instructions at https://docs.jfrog.com/releases/docs/jfrog-security-advisories and https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases, following CISA's BOD 26-04 guidance for prioritizing security updates. If mitigations are unavailable, discontinue use of the product for cloud services per BOD 26-04 requirements. Due date for patching is 2026-09-25.
Vulnerability Details
EPSS: 0.3%
Yes
๐ฅ Actively Exploited
September 10, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-42018
First tracked: September 11, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 72%