Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
AI Summary
Wiz Research has identified active in-the-wild exploitation of three vulnerabilities in JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329. Attackers are chaining CVE-2026-42018 and CVE-2026-42016 to escalate privileges from an unauthenticated state to admin access, while CVE-2026-82329 allows direct unauthenticated administrative access. Post-exploitation activities include creation of persistent admin accounts, deployment of malicious Groovy plugins, execution of ad-hoc commands, and installation of Rust-based backdoors for C2 communication. Multiple threat actors have been observed exploiting these flaws across self-hosted Artifactory instances, with evidence of configuration exfiltration, credential theft, and persistence mechanisms.
AI-extracted · verify before operational use
Indicators of Compromise 23 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 93[.]104[.]155[.]133 | Details → |
| Domain | log[.]gitclone[.]org | Details → |
| IP | 3[.]88[.]162[.]79 | Details → |
| IP | 64[.]207[.]232[.]6 | Details → |
| IP | 149[.]102[.]229[.]150 | Details → |
| IP | 186[.]247[.]79[.]240 | Details → |
| IP | 182[.]62[.]201[.]69 | Details → |
| IP | 146[.]19[.]216[.]120 | Details → |
| IP | 185[.]190[.]58[.]172 | Details → |
| IP | 45[.]61[.]176[.]88 | Details → |
| IP | 223[.]144[.]227[.]110 | Details → |
| IP | 129[.]121[.]56[.]234 | Details → |
| IP | 16[.]54[.]250[.]190 | Details → |
| IP | 105[.]188[.]75[.]16 | Details → |
| IP | 103[.]124[.]165[.]42 | Details → |
| IP | 176[.]88[.]121[.]152 | Details → |
| IP | 155[.]254[.]120[.]23 | Details → |
| IP | 220[.]246[.]124[.]92 | Details → |
| IP | 15[.]157[.]64[.]113 | Details → |
| IP | 104[.]28[.]251[.]139 | Details → |
| IP | 137[.]184[.]111[.]69 | Details → |
| Filename | /tmp/.z | Details → |
| SHA-1 | 513a907b69edffc3cb77a494da395178d21ef9bd | Details → |