← back

CVE-2026-42016

HIGH · 8.1 KEV EPSS 0.9%
hype ACTIVE HACK · 92 hack

KEV-listed; Wiz reports in-the-wild exploitation with C2 staging; CISA alert issued.

What: JFrog Artifactory Self Hosted (before v7.133.11) privilege escalation via improper token scope validation; CVSS 8.1 HIGH.

Why it matters: KEV-listed as of 2026-09-11 with confirmed active exploitation. Wiz Research documented in-the-wild chaining of CVE-2026-42016 with CVE-2026-42018 to achieve auth bypass, privilege escalation, and C2 backdoor deployment on self-hosted instances. CISA issued alert. Urgent patching required.

Where it's seen: CISA KEV alert, Wiz threat intel, Bleeping Computer coverage, security researcher posts describing live attack chains and Rust backdoor payloads. High engagement across Bluesky and threat feeds.

RISK: CRITICAL — Active exploitation chained with auth bypass; backdoor deployment; KEV-listed.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/12/2026, 6:43:13 AM

Description

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

CVSS 3.1 breakdown

Exploitability 2.8 · Impact 5.2
vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack vector
Network
Complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Weaknesses