JFrog Artifactory CVE-2026-42018 + CVE-2026-42016: Admin Chain
Attackers chained two JFrog Artifactory bugs - CVE-2026-42018 and CVE-2026-42016 - to forge administrator tokens without credentials, then planted Groovy plugins and Rust backdoors inside software bui
404-founders.com7 min read