FR
live
Critical Actively exploited

CVE-2026-82329

JFrog Artifactory

JFrog Artifactory Improper Authentication Vulnerability

What this means

Weakness
The authentication mechanism can be bypassed, letting an attacker pose as a legitimate user.
Likelihood
Exploitation is not hypothetical: CISA has observed it in the wild.

What to doTop priority: CISA sets the remediation deadline at 5 September 2026.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
2 September 2026
CVSS
EPSS
7.67% probability of exploitation within 30 days · above 94% of all CVEs
Weakness
CWE-287
CISA due date
5 September 2026
Sources
cisa-kev
References

Type at least two characters.

navigate open esc dismiss