JFrog 曝 Artifactory 严重认证绕过漏洞
Two days ago JFrog dropped CVE-2026-82329, a critical authentication bypass in A…
Two days ago JFrog dropped CVE-2026-82329, a critical authentication bypass in Artifactory.
两天前,JFrog 发布了 CVE-2026-82329,这是 Artifactory 中的一个严重认证绕过漏洞。
It’s a CVSS 9.8, a disastrous vulnerability score. It’s like a 9.8 earthquake on the seismic scale.
其 CVSS 评分为 9.8,这是一个灾难性的漏洞评分。就像地震等级中的 9.8 级地震一样。
It affects default configs, requires no auth, no user interaction. It’s an RCE bomb because Artifactory hosts binaries, so you can basically poison everything, but an admin escalation can cause damage even beyond that.
它影响默认配置,无需认证,无需用户交互。这是一个 RCE 炸弹,因为 Artifactory 托管二进制文件,所以基本上可以毒化一切,但管理员权限提升甚至可能造成更大的损害。
When the OpenAI / Hugging Face news came out of agents discovering zero-days, I was wondering if it was marketing-speak or reality, because I hadn’t seen a CVE filing. Now it’s here: https://www.cve.org/CVERecord?id=CVE-2026-82329.
当 OpenAI / Hugging Face 关于代理发现零日漏洞的消息传出时,我在想这是营销话术还是现实,因为我还没看到 CVE 备案。现在它来了:https://www.cve.org/CVERecord?id=CVE-2026-82329。
I don’t see any official confirmation that it’s indeed the case, but one can speculate this is what the agents discovered and exploited. I’d previously written that it was obvious agents could help in finding serious vulnerabilities *alongside humans*, but exploiting them autonomously was a bridge not yet crossed. It seems like we’re now there.
我没有看到任何官方确认确实如此,但可以推测这就是代理发现并利用的漏洞。我之前写过,很明显代理可以帮助人类发现严重漏洞,但自主利用它们是一座尚未跨越的桥梁。看来我们现在已经到达了那个阶段。
Our guidance for this new world: assume everything hackable will get hacked. And it will get hacked autonomously. You must also defend yourself autonomously, because your surface of attack is likely bigger and your code more vulnerable than you expect:
我们对这个新世界的指导是:假设一切可被黑客攻击的东西都会被黑客攻击。而且会被自主地黑客攻击。你也必须自主防御,因为你的攻击面可能比你预期的更大,你的代码也可能比你预期的更脆弱:
https://vercel.com/blog/everything-hackable-will-get-hacked
https://vercel.com/blog/everything-hackable-will-get-hacked
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力