CISA Flags Five Actively Exploited Flaws in Artifactory, ScreenConnect, and RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially listed five newly identified security flaws in its Known Exploited Vulnerabilities (KEV) catalog, citing evidence that threat actors are already leveraging these weaknesses in the wild. The vulnerabilities affect three widely deployed products: JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.
CISA maintains the KEV repository as a rapid‑response tool for federal agencies and the broader public‑private sector, highlighting flaws that have been observed in active attacks. Inclusion in the catalog signals that the agency considers the vulnerabilities to pose an immediate risk and that mitigation should be prioritized by organizations that rely on the affected software.
One of the flagged issues resides in JFrog Artifactory, a popular binary repository used to store and manage software components across development pipelines. Exploitation of this flaw could enable attackers to inject malicious artifacts, potentially compromising the integrity of downstream applications and disrupting supply‑chain security. Enterprises that host internal or public Artifactory instances are advised to verify that they are running patched versions and to monitor for unusual repository activity.
Another vulnerability targets ConnectWise ScreenConnect, a remote support and desktop‑sharing solution frequently employed by IT service providers. The flaw allows unauthenticated actors to gain remote access to systems that have the tool installed, raising concerns about data exfiltration and lateral movement within corporate networks. Organizations using ScreenConnect are urged to apply vendor‑released updates and to enforce strong authentication mechanisms for remote sessions.
The final set of flaws involves MikroTik RouterOS, the operating system that powers a large share of low‑cost networking equipment worldwide. Exploited instances have been reported to grant attackers command‑line control over routers, opening pathways to intercept traffic, launch denial‑of‑service attacks, or serve as footholds for broader network infiltration. Network administrators should audit device firmware levels, apply the latest security patches, and consider additional network‑segmentation controls.
CISA’s action underscores the accelerating pace at which vulnerabilities transition from discovery to exploitation. Security teams are encouraged to review the KEV entry, prioritize patch deployment, and incorporate threat‑intel feeds that reference these specific CVEs into their monitoring processes. As the agency continues to track exploitation trends, stakeholders can expect further advisories that aim to curb the impact of actively weaponized software defects.
Comments (0)
Be the first to comment.
Join the discussion