More JFrog Artifactory bugs under attack, and all 3 have patches
JFrog Artifactory instances are being targeted by attackers exploiting three vulnerabilities (CVE-2026-42018, CVE-2026-42016, CVE-2026-82329) despite patches being available. According to Wiz, 59% of organizations remain vulnerable to CVE-2026-42016, 62% to CVE-2026-42018, and 49% to CVE-2026-82329. Attackers are gaining admin access, installing backdoors, and exfiltrating data. JFrog has not commented on the attacks.
How this was made

The 30-second read
Why it matters
The exploitation details suggest heightened security risk, which could affect JFrog's revenue if customers delay or switch products.
Market read
Security flaws in a core DevOps product can drive short‑term stock volatility and influence enterprise security budgeting.
What to watch
The article does not quantify any direct financial loss or breach impact, and many customers may already have mitigated exposure.
Background
JFrog Artifactory is a widely used repository manager for binaries and container images. Recent CVEs have attracted active exploitation.
Market effects
Highlights broader supply‑chain security concerns for DevOps tools and may affect peers in the software‑delivery market.
Primarily impacts North American and European enterprise software markets where JFrog has significant exposure.
Raises awareness of software supply‑chain vulnerabilities globally, potentially influencing security spending trends.
Counterpoint
If JFrog's rapid patch releases and customer support are viewed positively, the news could be seen as a catalyst for trust and longer‑term demand.
Key entities
- CompanyJFrog Ltd.
Provider of Artifactory and other DevOps tools.
- Security ResearcherWiz
Reported the in‑the‑wild exploitation of the vulnerabilities.



