THREAT BRIEFING · 29.09.2026 DEENFRES

Practice & Implementation

Attacker accounts remain active after the Artifactory patch

By Benedikt Langer · September 26, 2026 · 8 min read

The US agency CISA gave federal agencies three days to close an exploited flaw in Citrix NetScaler. The catalog entry names a possible denial of service. Security researchers had already demonstrated code execution as root on the same product, presumably via the same flaw. Attacks on JFrog Artifactory and PaperCut have left traces that persist after patching.

Key takeaways

  • Admin accounts and plugins survive the upgrade. According to Wiz, admin accounts created in Artifactory and malicious Groovy plugins persist across restarts; the upgrade only closes the entry point.
  • Stolen signing keys remain valid. According to Wiz, the Access signing key private.key can be used to generate tokens for any user, and a patch does not revoke it. For such findings, Wiz recommends resetting the token certificate.
  • If compromise is suspected, a rebuild remains the answer. PaperCut recommends securing backups, rebuilding the Application Server from scratch and restoring a clean backup.

Deadlines for US agencies

On 26 August 2026, CISA added the vulnerability CVE-2026-8452 in Citrix NetScaler ADC and NetScaler Gateway to the Known Exploited Vulnerabilities Catalog and set US agencies a deadline of 29 August 2026 to comply. The entry describes the possible impact as denial of service and marks a forensic triage under BOD-26-04 as not required. It contains no information about effects on the system such as dropped files or new accounts.

Citrix lists NetScaler ADC and Gateway 14.1 before 14.1-72.61 as well as 13.1 before 13.1-63.18 as affected. In tests by watchTowr Labs, the vulnerability was exploitable when SAML is configured as a Service Provider or Identity Provider.

What is the KEV catalog? The Known Exploited Vulnerabilities Catalog is a list compiled by the US cybersecurity agency CISA of vulnerabilities with confirmed exploitation in the wild. For US agencies, inclusion comes with a remediation deadline; for CVE-2026-8452, three days.

Web shell on the NetScaler test appliance

On a NetScaler 13.1 test appliance, watchTowr shows how an oversized signature element in a SAML message overwrites heap memory and crashes the root packet process nsppe. The team also executes shellcode in the root process nsppe and drops the PHP web shell /var/vpn/theme/x.php. watchTowr considers the link to CVE-2026-8452 likely because Citrix describes the flaw as a memory overflow vulnerability.

After an nsppe crash, the process manager pitboss by default restarts the entire instance, and every dropped file is lost. Only because the shellcode neutralizes the signal handlers does pitboss restart just the nsppe process, and the web shell survives until the next full restart.

Minutes to an admin account

The cloud security company Wiz observed several attackers on self-hosted JFrog Artifactory instances from 15 August to 8 September 2026. They chained CVE-2026-42018, an exposed token of the internal anonymous user, with CVE-2026-42016, a flawed check of token permissions. The escalated token still carries the name of the anonymous account, so follow-up actions appear as token:anonymous. In individual cases, under five minutes passed between the first request and a new admin account.

A third critical Artifactory flaw, CVE-2026-82329, grants admin rights without authentication under the default configuration. Between 1 and 8 September 2026, Wiz observed several successful exploitations, each via a POST to /access/api/v1/registry/join that returned HTTP 200 or 201 with an admin token in the response body.

After the initial entry, Wiz observed persistent admin accounts across different attackers, some disguised as jfrog-distribution, backup-service, repo-service or ldap_admin. Individual attackers installed malicious Groovy plugins or a Rust backdoor connecting to a command and control server; others stole the platform’s Join Key after exploiting CVE-2026-82329 and generated long-lived tokens. The Groovy plugins can also harvest the Access signing key private.key. Whoever holds it can, according to Wiz, generate permanently valid tokens for any user even after patching.

When CVE-2026-42016 was published at the end of July, 67 percent of organizations with Artifactory in the environments Wiz monitors had at least one vulnerable instance; six weeks later the figure was still 59 percent. Wiz advises updating internet-facing instances first and restricting network access to trusted users and systems. Each version branch has its own patched release, from 7.111.21 in the oldest to 7.161.20 in the newest branch.

PaperCut patches and indicators of compromise

In its security bulletin, the print management vendor PaperCut rates the authentication bypass CVE-2026-81578 at CVSS 8.8. It lets an attacker change certain system configurations without authentication. The bulletin also names CVE-2026-82078, unsafe dynamic class loading in the database connector, at CVSS 9.4.

The regular maintenance versions 26.0.5, 25.0.13 and 24.1.10, released on 10 September 2026, replace all emergency patches released between 28 August and 1 September. PaperCut recommends them to all customers, even when the server is not reachable from the internet. Anyone still running the first or second emergency patch should update immediately, according to the vendor. The emergency patches reported the same version number as the unpatched build, so the notice in the product could not tell patched and unpatched servers apart.

As indicators of compromise, the vendor lists missing, unexpectedly truncated or deleted server.log files, log lines such as “DB URL: jdbc:derby:memory:pwn;create=true” as well as class files with five-character names in server\lib and matching .cmd or .out files in the data directory. Attackers can remove these files in the course of an attack, so their absence does not rule out a compromise.

In the observed cases, the process pc-app.exe launched the shell cmd.exe with whoami and ver. Where endpoint protection did not intervene, a documented command sequence downloaded ace.exe from sendit.sh, installed the Windows service Remote Access Service with the SimpleHelp agent SimpleService.exe as LocalSystem with autostart and downloaded AnyDesk. If compromise is suspected, PaperCut recommends securing backups, rebuilding the Application Server from scratch and restoring a clean backup.

Triage required for Switchvox

On 2 September 2026, CISA added the flaw CVE-2026-9586 in the Sangoma Switchvox phone system to the KEV catalog and, in this case, marked a forensic triage under BOD-26-04 as required. The SQL injection lets an attacker execute arbitrary SQL statements against the PostgreSQL database with a single crafted request and no authentication, up to remote code execution. The entry lists 5 September 2026 as the deadline for agencies.

For NetScaler, CISA does not require forensic triage; for Switchvox it does. The documented attacks on Artifactory and PaperCut left their traces in accounts, plugins, services and keys, which need to be checked before the maintenance window closes. Whether accounts in the style of jfrog-distribution or a SimpleHelp service exist on the PaperCut server is something the patch level does not show.

Frequently asked questions

Every question is collapsed. Tapping it reveals the answer.

Why isn’t a security update enough after an attack?

An update replaces the vulnerable software. It does not remove accounts, services and plugins that an attacker set up beforehand. With PaperCut, for example, attackers installed a Windows service with the SimpleHelp agent as LocalSystem that starts on every system boot.

What traces has Wiz documented after Artifactory attacks?

Across different attackers, Wiz observed malicious Groovy plugins, a Rust backdoor connecting to a command and control server and persistent admin accounts with inconspicuous names such as jfrog-distribution or repo-service. After exploiting CVE-2026-82329, some attackers also stole the Join Key and generated long-lived tokens.

What does PaperCut recommend if compromise is suspected?

The vendor recommends completely rebuilding the Application Server from a clean backup. Indicators include missing or truncated server.log files, log lines such as “DB URL: jdbc:derby:memory:pwn;create=true” and class files with five-character names in server\lib. Their absence does not rule out a compromise because attackers can remove these files in the course of an attack.

More from the MBF Media Network

cloudmagazin18 months without a fix: How an Argo CD vulnerability exposed the entire Kubernetes clusterDigital ChiefsFalse Sense of Security: When Cyber Police Fail to Act in a Real Emergency

Image source: AI-generated (September 2026)

Further reading

Practice & Implementation · July 31, 2026

Anthropic: Claude Breached Three Companies

Anthropic's Claude compromised three organizations in cyber evaluations. Harness misconfiguration, PyPI malware, and CISO checklist insights.

Practice & Implementation · July 29, 2026

Codex Security: Open Client Feeds OpenAI

Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.

A magazine by Evernine Media GmbH