DIRAS TAKE
Urgent: CISA added this vulnerability to its KEV catalog with a remediation due date, signalling immediate prioritization; apply the vendor fix or mitigations without delay for internet-facing Artifactory instances.
What is CVE-2026-42016?
A low-privileged network attacker can escalate privileges on JFrog Artifactory by exploiting an incorrect authorization check that validates token signature/issuer but not token scope; this is CVE-2026-42016. The flaw affects Artifactory 7.x before 7.133.11. An attacker needs network access to the service and a valid low-privilege account on an affected instance to trigger the issue.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of JFrog Artifactory are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | before 7.133.11 | 7.133.11 |
Is CVE-2026-42016 being exploited?
CISA added CVE-2026-42016 to the Known Exploited Vulnerabilities catalog on 2026-09-11, and U.S. federal agencies were required to remediate it by 2026-09-25.
How to fix CVE-2026-42016
- Upgrade Artifactory 7.x to 7.133.11.
- If you cannot upgrade immediately, restrict network exposure of Artifactory and limit reachable accounts.
- Follow JFrog’s vendor guidance and apply any recommended configuration mitigations.
- Monitor authentication and privilege-change logs for signs of misuse.
Frequently asked questions
Is CVE-2026-42016 being actively exploited?
CISA added CVE-2026-42016 to its Known Exploited Vulnerabilities catalog on 2026-09-11, and federal agencies were required to remediate it by 2026-09-25.
Which Artifactory versions are affected by CVE-2026-42016?
Artifactory 7.x versions before 7.133.11 are affected by CVE-2026-42016.
Is there a patch for CVE-2026-42016?
Yes. JFrog fixed the issue in Artifactory 7.133.11; upgrade to 7.133.11.
Does CVE-2026-42016 require authentication?
Yes. Exploitation requires a valid low-privilege account on the affected Artifactory instance.
References
- nvd.nist.gov/vuln/detail/CVE-2026-42016
- cve.org/CVERecord?id=CVE-2026-42016
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016
- docs.jfrog.com/releases/docs/jfrog-security-advisories
- docs.jfrog.com/releases/docs/artifactory-self-managed-releases
- All JFrog CVEs on CVE Radar
- CVEs published in September 2026