Three Artifactory vulnerabilities under active exploitation enable authentication bypassing on Internet-accessible, self-hosted deployments, potentially allowing attackers to establish persistent administrator access in under five minutes. The exploits then enable dangerous activity, including credential and key theft, arbitrary code execution, persistence, and anti-forensics measures. By Sergio De Simone