{"type":"bundle","id":"bundle--7a3f651f-3dcf-548b-b570-5e9e9a01c56b","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--3218eee9-ff6b-5b14-a3f2-4c1197d017be","created":"2026-09-20T18:52:59.848Z","modified":"2026-09-20T18:52:59.848Z","name":"Artifactory anonymous token chain (CISA KEV)","description":"Self-hosted JFrog Artifactory could hand an internal anonymous-user token to an unauthenticated caller even when anonymous access was disabled, opening a path into sensitive resources. CISA KEV and public in-the-wild reporting apply. Upgrade past the fixed builds for your Artifactory train and rotate credentials if exposure is plausible.","aliases":["CVE-2026-42018","Artifactory anonymous token exposure","CVE-2026-42016"],"first_seen":"2026-09-11T00:00:00.000Z","last_seen":"2026-09-11T19:25:36.274Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"CISA KEV catalog entry","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018"},{"source_name":"Wiz in-the-wild Artifactory exploitation write-up","url":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"},{"source_name":"NVD CVE-2026-42018","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42018"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-42018-artifactory-anonymous-token-kev-chain"}]}]}