CVE-2026-42018
- CVSS
- —
- EPSS
- —
- CISA KEV
- Added 2026-09-11, due 2026-09-25
- Exploitation
- No report
- Public exploits
- None seen
- State
- Unknown
Coverage
Actively exploitedCISA advisories & alerts
CISA Adds Three Known Exploited Vulnerabilities to Catalog(opens the publisher's site in a new tab)
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-84869…

Actively exploitedWiz Research
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329(opens the publisher's site in a new tab)
Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining these vulnerabilities to bypass authentication and gain administrative control.
What we observed
- kev addedcisa-kev