Attackers Chain Artifactory Vulnerabilities to Take Over Repositories

DedicatedLinux

On September 10, 2026, Wiz Research reported that multiple attackers had chained two Artifactory vulnerabilities against self-hosted repositories. One flaw gave an unauthenticated caller an internal anonymous token. The other let that caller exchange the limited token for administrator rights. Wiz observed the resulting access being used to create persistent administrators, load hostile Groovy plugins, place web shells, and install Rust backdoors.LinuxSecurity – Security ArticlesRead More