CRITICAL: JFrog Artifactory CVE-2026-82329 Exploited to Mint Admin Tokens
JFrog Artifactory instances running default configurations hand unauthenticated attackers a path to full administrator access through what researchers call a phantom join key. CISA added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog after watchTowr observed attackers minting admin tokens in the wild, four days after the patch shipped.