Artifactory Is Under Active Attack: 3 Checks in 30 Minutes A research report published Thursday details four weeks of active exploitation of JFrog Artifactory, in which attackers chain two patched CVEs to escalate a single unauthenticated request into an admin-scoped token. CISA has added all three related CVEs to its Known Exploited Vulnerabilities catalog, with a federal remediation deadline of September 25 for two of them. A developer cross-checked the NVD and KEV records and built a three-check, roughly 30-minute audit plan from Wiz's published IOCs and version ranges, noting the checks have not been run against a live instance. A research report published Thursday describes four weeks of active exploitation of JFrog Artifactory, the artifact registry that sits in front of most Java and DevOps build pipelines. Attackers chain two patched CVEs to turn a single unauthenticated request into an admin-scoped token, and the tell is uncomfortable: every request they make afterward shows up in your logs as token:anonymous , an actor name that looks exactly like background noise. CISA has all three CVEs on the Known Exploited Vulnerabilities catalog, and the federal remediation deadline for two of them is September 25. I write about MCP and tooling security here, and before trusting any report I cross-check it against primary records. The three NVD records and the KEV feed hold up: the privilege escalation is scored 8.1 by the vendor and 8.8 by NVD, the token exposure 7.5, the default-config admin bypass 9.8. What the records do not give you is an audit plan, so I built one from the Wiz IOC table and the version ranges. Three checks, about thirty minutes. One honesty note before we start: I derived these from the published IOCs and ranges, I have not run them against a live instance, so treat every log path here as a starting point to adapt. First, the version. Everything else depends on it: self-hosted instance version, for the range checks below use a token your automation already holds; if this endpoint is admin-restricted on your build, read the version from the admin UI instead curl -s -H "Authorization: Bearer $ARTIFACTORY TOKEN" \ "https://artifactory.internal.example/artifactory/api/system/version" Between August 15 and September 8, Wiz observed multiple actors chaining two CVEs against self-hosted Artifactory instances. The chain has three moves: POST /access/api/v1/aws/token/ , with a trailing slash. The bare path rejects callers with a 401. The trailing-slash variant returned HTTP 200 with a JWT for the internal anonymous user, even when anonymous access was disabled. That is CVE-2026-42018. POST /access/api/v1/tokens . The actor exchanges that JWT for an admin-scoped token. The flaw here is scope validation: the token's signature and issuer are checked, its intended scope is not. That is CVE-2026-42016. PUT /api/security/users/