Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
2026-09-02T19:23:21Z•5a441dc0f7af8df00097bdd1d1589c4d1bec0ca92571c63b6e0f16d253d55cb4
CVE-2026-0768CVE-2026-82329ATM jackpottingBGP hijackingDarkVNCJFrog ArtifactoryLangflowMicrosoft ExchangeSality botnetScreenConnectSonicWall SMA1000TVRATactive exploitationauthentication bypasscredential theftdata breachhealthcaremalwarephishingransomwareremote code executionsupply-chain compromisetoken forgery
What happened
A BleepingComputer security-news feed highlights active exploitation of critical vulnerabilities, including JFrog Artifactory authentication bypass (CVE-2026-82329) enabling forged administrative tokens and Langflow unauthenticated RCE (CVE-2026-0768) used to steal OpenAI and AWS credentials. It also reports actively exploited SonicWall SMA1000 zero-days, widespread exposure of unpatched Microsoft Exchange servers, phishing and legitimate-tool abuse, supply-chain and BGP hijacking attacks, malware campaigns, botnet disruption, and significant healthcare and account-data breaches.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 5a441dc0f7af8df00097bdd1d1589c4d1bec0ca92571c63b6e0f16d253d55cb4
- Enrichment time
- 2026-09-02T19:23:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.