Artifactory instances without a join key were given a phantom one. Attackers were minting admin tokens three days after the fix
2026-09-03Security
CVE-2026-82329 lets an unauthenticated attacker forge credentials and mint administrator tokens against JFrog Artifactory, and the vulnerable state is the default one. The patch landed on 28 August; watchTowr saw exploitation from 1 September, including actors creating backdoor users.