OpenInfra Europe Artifactory breach puts packages at risk
Attackers broke into a self-hosted JFrog Artifactory instance run by OpenInfra Europe and gained admin access. Packages served from it may have been tampered with. OpenInfra Europe, the regional hub of the OpenInfra Foundation, disclosed the incident in a security notice placed prominently on its homepage.
The warning is aimed at anyone who pulled software from the affected server during a specific window.
"Anyone who downloaded or installed artifacts from https://artifactory.nordix.org/ from August 28 and September 15, 2026 should immediately stop using them, remove them from their pipelines, and treat these packages as potentially compromised," the notice reads.
Who runs the affected system
The OpenInfra Foundation belongs to the non-profit Linux Foundation. It hosts and supports open source projects used to run cloud and datacenter infrastructure. Its best-known project is OpenStack, an open source platform for building private and public clouds.
The breached system was a JFrog Artifactory deployment. Artifactory is a binary repository manager. Development teams use it to store and serve build outputs and the dependencies their software relies on. Organizations can host it on their own servers or use it as a Software-as-a-Service product. OpenInfra Europe ran its own instance.
This is why the incident matters beyond a single server. A repository manager sits in the middle of the software supply chain. Whatever it hands out ends up in other people's builds and deployments.
An authentication bypass opened the door
According to OpenInfra Europe, the instance was running a vulnerable version of Artifactory. That left it exposed to CVE-2026-82329, an authentication bypass flaw that unauthenticated attackers can exploit.
The attackers used it to get into the instance and obtain admin privileges. With that level of access, they could tamper with the deployment itself, as well as with the artifacts, credentials and integrations it manages.
The timeline was short:
- August 28, 2026: CVE-2026-82329 is publicly disclosed
- August 31: in-the-wild exploitation begins, according to various sources
- August 31: OpenInfra Europe's Artifactory instance is compromised
- September 2: CISA adds the flaw to its Known Exploited Vulnerabilities (KEV) catalog
- September 15: the breach is discovered
CISA is the US Cybersecurity and Infrastructure Security Agency. Its KEV catalog lists flaws confirmed to be exploited by attackers and is widely used as a signal to patch urgently.
Attackers moved on the flaw within days of disclosure. The OpenInfra Europe server was hit on the same day exploitation reportedly started.
Found only after a user was locked out
The intrusion went unnoticed for about two weeks. OpenInfra Europe says it was discovered on September 15, "after a legitimate user was denied access."
The organization says it isolated the affected system immediately and began an investigation. It has not yet determined the full scope and impact of the incident.
That leaves downstream users with an open question: which artifacts, if any, were altered, and whether credentials or integrations connected to the instance were also exposed. Until the investigation provides answers, OpenInfra Europe's advice is to treat everything downloaded in the window as untrusted.
In practice, that means teams that pulled from artifactory.nordix.org between August 28 and September 15 should find where those artifacts ended up. They should then remove them from build and deployment pipelines and replace them with copies obtained from a trusted source.
Our Take
This incident shows how quickly a newly disclosed flaw can become a supply chain problem. The gap between public disclosure and the compromise was three days, and the breach was noticed only by accident. For organizations running self-hosted developer tooling, this suggests that patch cycles measured in weeks are no longer enough for internet-facing systems of this kind.
It also fits a pattern we have seen repeatedly this year. Attackers are targeting the infrastructure developers rely on, from build servers like TeamCity to weaknesses that let attackers push code into repositories. A compromised repository manager can pass tampered packages to many downstream users at once.
It is worth watching whether OpenInfra Europe's investigation confirms that any artifacts were actually modified, and whether credentials stored on the instance were abused elsewhere. Other self-hosted Artifactory operators may also discover similar intrusions, given how fast exploitation of CVE-2026-82329 appears to have started. As with the Citrix NetScaler flaw now under mass attack, a KEV listing should be treated as a reason to also check for signs of compromise, not just to patch.
