JFrog Artifactory piles up two exploited authentication flaws, and your binary registry is the next link
On September 11, 2026, CISA added two JFrog Artifactory flaws to the KEV catalog: CVE-2026-42016, which validates a token’s signature without checking its scope, and CVE-2026-42018, which leaks an anonymous token even when anonymous access is disabled. Upgrade to 7.133.11, revoke the affected tokens and audit anonymous access before a poisoned artifact ships to production.