wiz · Crawled Sep 11, 2026

Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329

23 IoCs
Read original article ↗

AI Summary

Wiz Research has identified active in-the-wild exploitation of three vulnerabilities in JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329. Attackers are chaining CVE-2026-42018 and CVE-2026-42016 to escalate privileges from an unauthenticated state to admin access, while CVE-2026-82329 allows direct unauthenticated administrative access. Post-exploitation activities include creation of persistent admin accounts, deployment of malicious Groovy plugins, execution of ad-hoc commands, and installation of Rust-based backdoors for C2 communication. Multiple threat actors have been observed exploiting these flaws across self-hosted Artifactory instances, with evidence of configuration exfiltration, credential theft, and persistence mechanisms.

AI-extracted · verify before operational use

Indicators of Compromise 23 extracted

Type Value Detail
IP 93[.]104[.]155[.]133 Details →
Domain log[.]gitclone[.]org Details →
IP 3[.]88[.]162[.]79 Details →
IP 64[.]207[.]232[.]6 Details →
IP 149[.]102[.]229[.]150 Details →
IP 186[.]247[.]79[.]240 Details →
IP 182[.]62[.]201[.]69 Details →
IP 146[.]19[.]216[.]120 Details →
IP 185[.]190[.]58[.]172 Details →
IP 45[.]61[.]176[.]88 Details →
IP 223[.]144[.]227[.]110 Details →
IP 129[.]121[.]56[.]234 Details →
IP 16[.]54[.]250[.]190 Details →
IP 105[.]188[.]75[.]16 Details →
IP 103[.]124[.]165[.]42 Details →
IP 176[.]88[.]121[.]152 Details →
IP 155[.]254[.]120[.]23 Details →
IP 220[.]246[.]124[.]92 Details →
IP 15[.]157[.]64[.]113 Details →
IP 104[.]28[.]251[.]139 Details →
IP 137[.]184[.]111[.]69 Details →
Filename /tmp/.z Details →
SHA-1 513a907b69edffc3cb77a494da395178d21ef9bd Details →