security3 distinct publishers
Attackers mint Artifactory admin tokens four days after JFrog shipped the fix
CVE-2026-82329 is a CVSS 9.8 authentication bypass in JFrog Access that needs no credentials against a default install. watchTowr is so far the only firm reporting that anyone is using it in anger.
Perspective Coverage
3 publishers- Builder
- Builder 35%
- Operator
- Operator 53%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption34
- Hype gap+16