← Back to blog
Blog Detail

CVE-2026-42018: JFrog Artifactory Improper Authentication Added to CISA KEV

CISA added CVE-2026-42018, an improper authentication flaw in JFrog Artifactory, to the KEV catalog on 2026-09-11 with a federal remediation due date of 2026-09-25. Patch or mitigate now.

Trusteed Team
Trusteed Editorial
Written On
Sep 18, 2026
Category
CTEM
Read Time
5 min read
  • CVE-2026-42018
  • KEV
  • CISA
  • JFrog
  • Artifactory
  • CWE-287
  • improper authentication
  • BOD 26-04

CVE-2026-42018: JFrog Artifactory Improper Authentication Added to CISA KEV

TL;DR

CISA added CVE-2026-42018, an improper authentication vulnerability in JFrog Artifactory, to the Known Exploited Vulnerability (KEV) catalog on 2026-09-11, with a federal remediation due date of 2026-09-25. If you run Artifactory — self-managed or as a service — inventory it today, apply the vendor's mitigations or update, and confirm that anonymous access is disabled and behaving as expected. Treat this as an actively exploited issue, not a theoretical one.

What is this vulnerability?

  • CVE ID: CVE-2026-42018
  • Vendor / product: JFrog / Artifactory
  • Vulnerability name: JFrog Artifactory Improper Authentication Vulnerability
  • Weakness: CWE-287 (Improper Authentication)
  • CISA KEV status: Yes — added 2026-09-11
  • CISA due date: 2026-09-25
  • CVSS (per JFrog, v3.1): 7.5 — HIGH (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
  • EPSS (Watchstack): 0.0092 (percentile ~0.586)
  • Known ransomware use: Unknown

What it does: According to the official summary, JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled. In practice, that means an unauthenticated attacker may be able to obtain a token that grants access to sensitive resources — even in environments where administrators believe anonymous access is turned off. The CVSS vector confirms the network-reachable, no-privileges-required, no-user-interaction profile that makes this attractive to opportunistic exploitation.

KEV vs CVSS vs EPSS

Signal What it measures How to use it for this CVE
CISA KEV Confirmed in-the-wild exploitation against known deadlines Primary driver. CVE-2026-42018 is KEV-listed with a due date of 2026-09-25. Treat as exploited; prioritize over non-KEV items regardless of score.
CVSS 7.5 (HIGH) Theoretical severity of the flaw's technical impact Confirms network-reachable, unauthenticated, high-confidentiality impact. Use to justify emergency change windows and cross-team escalation.
EPSS 0.0092 (~58.6th percentile) Statistical probability of exploitation in the next 30 days Low relative score. Do not use this to deprioritize — KEV listing supersedes EPSS for prioritization. EPSS lags real-world exploitation signals.

Bottom line: KEV wins. If your patch queue is ranked purely by EPSS or CVSS, this CVE will be under-ranked. Re-rank it manually.

Step-by-step remediation

  1. Inventory. Enumerate every JFrog Artifactory instance across your estate — self-managed deployments, cloud/self-hosted, and any embedded or developer-managed instances. Include CI/CD runners, artifact mirrors, and edge caches that may proxy Artifactory. Note internet exposure for each.
  2. Patch or mitigate. Apply the vendor's guidance from the JFrog security advisories and self-managed release notes. Where an immediate update is not possible, apply the mitigations JFrog prescribes. Follow CISA's BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
  3. Verify. After remediation, confirm the fix is in place: check the running version against the vendor advisory, and validate that anonymous access is disabled and that no anonymous-user token is returned to unauthenticated callers. Re-test any internet-facing instance specifically.
  4. Hunt for exposure. Review Artifactory access logs for unauthenticated requests that received tokens or accessed sensitive resources, especially in the window before patching. Escalate anything suspicious to incident response and follow CISA's Forensics Triage Requirements.
  5. Ticket closure. Document the version applied, the mitigation steps taken, the verification evidence, and the exposure assessment. Close the ticket only after verification — not after the change window opens.

FAQ

Is CVE-2026-42018 in CISA KEV? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-11, indicating confirmed exploitation in the wild.

What is the CISA due date for CVE-2026-42018? The federal remediation due date is 2026-09-25. Federal civilian agencies must remediate by that date under BOD 26-04; private-sector defenders should treat it as an aggressive internal SLA.

Is this vulnerability internet-facing / remotely exploitable? The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates network-reachable exploitation with no privileges or user interaction required. Any Artifactory instance reachable from untrusted networks should be considered high priority. Evaluate each asset's internet exposure as part of your BOD 26-04 compliance.

Is there a ransomware tie? CISA's KEV entry does not list known ransomware use for this CVE. That does not reduce urgency — KEV listing alone means active exploitation.

What is the CVSS score and severity? CVSS 3.1 base score of 7.5 (HIGH), per JFrog, with high confidentiality impact and no integrity or availability impact.

What is the EPSS score, and should it change my prioritization? EPSS is 0.0092 (~58.6th percentile). No — KEV listing overrides EPSS for prioritization. Patch on the KEV timeline.

Related resources

Join Our Newsletter

Trusteed keeps you informed: emerging risks, platform updates, and practical guides for faster defense.