Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

JFrog patched three server vulnerabilities exploited to create admin accounts.

Attackers exploited three vulnerabilities in JFrog Artifactory to deploy backdoors on self-hosted instances, SecurityWeek reported.

ERP LEADERS news desk · · First reported by SecurityWeek · Edition no. 8

The flaws had been patched months earlier.

CVE-2026-42016 was fixed on 27 July. CVE-2026-42018 followed on 12 August, then CVE-2026-82329 on 28 August.

Between mid-August and early September, attackers chained CVE-2026-42018 with CVE-2026-42016 against self-hosted instances. They created persistent admin accounts and installed malicious plugins. From there, they ran shell commands and dropped additional payloads.

Other actors used CVE-2026-82329 to steal configuration and mint tokens. They also exfiltrated cluster keys. SecurityWeek states that CISA added all three flaws to its Known Exploited Vulnerabilities catalog.

The designation under BOD 26-04 gives federal agencies two weeks to patch. An artifact repository is where builds originate. An admin account there signs whatever the pipeline ships next.

When did you last patch the systems that build your software, rather than the ones that run it?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story
JFrog

For your next steering committee

Questions for your own programme. They are not findings about any company in this story.

  1. 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
  2. 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
  3. 3Ask how long a restore took the last time it was tested.

Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01

Founding reader view is on in this browser. It is a reading view, not secure access. Print the working sheet

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01