Wiz Research identified active in-the-wild exploitation of three critical vulnerabilities in JFrog Artifactory (CVE-2026-42016, CVE-2026-42018, CVE-2026-82329) that allow attackers to bypass authentication and gain administrative control. Attackers are chaining these flaws to deploy persistent backdoors and malicious plugins, with 49-62% of organizations remaining vulnerable weeks after disclosure.
Security researchers identified vulnerabilities in coding agents that execute code before the model makes decisions, including Git configuration exploits and gateway authentication bypasses. Three security boundaries—runtime, gateway, and tools—must be enforced, with workspace trust and startup restrictions implemented before any model interaction occurs.