Cyber Resilience
← All news
Confirmed

JFrog security advisory (AV26-867)

Our takeCanadian Centre for Cyber Security reports active exploitation of CVE-2026-82329 in JFrog Artifactory. Patch if you self-host (some enterprises); most small teams use the hosted service and can ignore this one.
Sources (3)
What this means for you — Security leader:Update all self-hosted Artifactory instances to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 or 7.161.20 (or later). Canadian Centre for Cyber Security confirms active exploitation of CVE-2026-82329.
What this means for you — Lean IT orgs:If you self-host JFrog Artifactory, update it to one of the fixed versions listed above. Most lean-IT teams use the hosted service and can ignore this one.
What this means for you — MSP:Audit client Artifactory inventories for self-hosted instances running any version prior to the fixed releases and patch immediately; hosted SaaS instances are unaffected.
What this means for you — Researcher:JFrog Artifactory prior to the listed patched releases is actively exploited per CCCS advisory AV26-867; CVE-2026-82329.