Home / Sep 13, 2026 / Story
0
#2 BleepingComputer general September 11, 2026 at 16:29 UTC

Artifactory flaws chained in attacks deploying backdoor malware

By Bill Toulas

AI Summary

Threat actors are actively chaining critical and high-severity vulnerabilities in JFrog Artifactory — including CVE-2026-42016 (CVSS 8.1) — to bypass authentication, escalate to administrative privileges, and deploy a Rust-based backdoor on self-hosted servers. CISA added these flaws alongside ConnectWise ScreenConnect and MikroTik RouterOS vulnerabilities to its KEV catalog, confirming active exploitation. Security teams running self-managed Artifactory instances should treat patching as urgent given the confirmed backdoor deployment.

Relevance score: 87.0/100

# More from September 13