JFrog Artifactory CVE-2026-82329 enters KEV: default configuration can expose admin access
Published 09 Sep 2026 · Severity: critical
CISA added CVE-2026-82329 to KEV on 2 September 2026. JFrog rates the issue critical: under default configuration, an unauthenticated attacker with network access may obtain Artifactory administrative privileges. JFrog Cloud environments were fortified by the vendor; self-hosted deployments need a fixed build and compromise-focused review.