MemTensor's Latest Tag Was the Implant. Clean Builds Lasted Minutes.
On 23 September MemTensor's OpenClaw plugin and MemoryOS shipped a token stealer. Clean builds lasted minutes. Pulling the versions did not end the impact clock.
CISA listed CVE-2026-42016 and CVE-2026-42018 as KEV on 11 September. Wiz saw the two-bug chain in the wild from 15 August. Federal due date is 25 September.
CISA added two JFrog Artifactory bugs to the Known Exploited Vulnerabilities catalog on 11 September: CVE-2026-42016 and CVE-2026-42018. Wiz saw those two chained against self-hosted instances from 15 August through 8 September. Federal civilian agencies have until 25 September. This is not the July OpenAI Artifactory path.
CISA added two JFrog Artifactory defects to the Known Exploited Vulnerabilities catalog on 11 September: CVE-2026-42016 and CVE-2026-42018. The operator document is the KEV JSON. Due date 25 September. Forensic triage: No. Wiz had already watched the two-bug chain run from 15 August.
High Actively exploited authentication and authorization bugs in a package registry that holds your build credentials. High because the chain is live and patching is slow, not because this is the July OpenAI eval path.
The 11 September alert names three CVEs. Two are Artifactory. The third is CVE-2026-84869 in ConnectWise ScreenConnect, due 14 September, with forensic triage required. Do not skip that one if you run ScreenConnect clients. The lead here is the registry.
CISA's short text is enough to act on:
A third Artifactory bug, CVE-2026-82329, is not in Thursday's alert because CISA already listed it on 2 September. Due date 5 September. Forensic triage: Yes. Under the default configuration, an unauthenticated caller with network reach can obtain administrative privileges. That clock has already expired.
Wiz published on 10 September and corrected a couple of version and method details the next afternoon. The window that matters is 15 August through 8 September. Multiple actors, not one crew, chained 42018 and 42016 against self-hosted instances. Neither CVE is admin by itself. Together they turn an unauthenticated request into an admin-scoped token. In some cases Wiz timed first request to a created admin account at under five minutes.
What they did with admin varies. Across victims: persistent administrator accounts, malicious Groovy plugins for code execution on the server, a custom Rust backdoor with C2, and occasional web shells dropped into a repository path. Between 1 and 8 September, other actors used 82329 on its own. watchTowr told The Register that 82329 scanning started four days after JFrog disclosed it.
Patching is the other number. At disclosure, Wiz saw vulnerable Artifactory in 67 percent of orgs that run it for 42016, 69 percent for 42018, 67 percent for 82329. Six weeks later, 59 percent still had 42016. Four weeks later, 62 percent still had 42018. Two weeks later, 49 percent still had 82329. Attackers waited for the patches, then raced the people who had not applied them.
| Product | Affected | Fixed in |
|---|---|---|
| Artifactory CVE-2026-42016 | Self-hosted builds before 7.133.11 | 7.133.11 or later on that branch |
| Artifactory CVE-2026-42018 | Before 7.111.20; 7.117.0-27; 7.125.0-19; 7.133.0-28; 7.146.0-8 | 7.111.20, 7.117.28, 7.125.20, 7.133.29, 7.146.9 or later |
| Artifactory CVE-2026-82329 | 7.111.4-21; 7.117.0-27; 7.125.0-19; 7.133.0-28; 7.146.0-36; 7.161.0-19 | 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20 or later |
| ScreenConnect CVE-2026-84869 | Clients before 26.6.5. Servers are not impacted. | 26.6.5. Temporary: remove TransferFiles from roles. |
If you run self-hosted Artifactory, or you consume packages from one you do not patch yourself:
CISA's catalog is a due date for federal networks. For everyone else it is evidence. The chain has been live since mid-August. A registry you have not patched is already on the wrong side of that evidence.
No. The July Hugging Face incident used a different set of Artifactory defects that JFrog patched in the 7.161.15 line. CVE-2026-42016 and CVE-2026-42018 are later authentication and scope bugs. CISA listed them because humans are exploiting them now, not because an eval agent found them.
No. CISA's text for CVE-2026-42018 is that Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Wiz's in-the-wild chain starts from that token, then uses CVE-2026-42016 to widen its scope.
CISA already listed it on 2 September, due 5 September, with forensic triage required. Wiz confirmed in-the-wild use from 1 to 8 September. If your instance is still on a vulnerable 7.161, 7.146, or earlier branch, that clock has already run out.
Unexpected administrator accounts, especially names that look like JFrog services. New Groovy plugins. Tokens minted by the anonymous identity that then acted as admin. Wiz also published payload hosts and a short list of actor addresses. Pull internet-exposed Artifactory off the public net while you do that.
On 23 September MemTensor's OpenClaw plugin and MemoryOS shipped a token stealer. Clean builds lasted minutes. Pulling the versions did not end the impact clock.
Accomplish found two Codex sandbox escapes. Heapjack ran host commands from read-only. Overpatch wrote outside the workspace. OpenAI fixed both in eight days.
Hacker News: SafeDep found an npm mathjs clone whose solver unlocks a RAT. JFrog cracked the trigger. The GitHub tree was clean. The tarball was not.