WorkThe story, in brief

Artifactory Vulnerabilities Under Active Exploitation Enable Authentication Bypass and Admin Access

Three Artifactory vulnerabilities under active exploitation—enabling admin access in under five minutes on self-hosted instances. If you run it on the internet, patch now.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

Critical infrastructure vulnerability hitting artifact repositories used across enterprise DevOps and CI/CD pipelines. Active exploitation means this is not theoretical; enterprises with internet-facing Artifactory deployments face immediate risk of credential theft, code injection, and persistence.

The key facts

11 to know
  1. Three Artifactory vulnerabilities confirmed under active exploitation

  2. Authentication bypass enabling administrator access in under five minutes

  3. Affects self-hosted, Internet-accessible Artifactory deployments

  4. Post-compromise risks: credential theft, arbitrary code execution, persistence, anti-forensics

  5. Reported by Sergio De Simone, InfoQ, 28 September 2026

  6. Three vulnerabilities under active exploitation

  7. Self-hosted Artifactory deployments affected

  8. Internet-accessible instances vulnerable

  9. Admin access achievable in under five minutes

  10. Enables credential and key theft, arbitrary code execution, persistence, anti-forensics

  11. Authentication bypass is the attack vector

Go to the source

InfoQ AI/MLinfoq.com

Publisher excerpt: Three Artifactory vulnerabilities under active exploitation enable authentication bypassing on Internet-accessible, self-hosted deployments, potentially allowing attackers to establish persistent administrator access in under five minutes. The exploits then enable dangerous activity, including…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work