$ techbeacon▋
CVE & Exploits

CISA Expands Known Exploited Vulnerabilities List to Include GitLab, JFrog Artifactory and ConnectWise ScreenConnect Flaws

CISA Expands Known Exploited Vulnerabilities List to Include GitLab, JFrog Artifactory and ConnectWise ScreenConnect Flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added vulnerabilities affecting GitLab, JFrog Artifactory and ConnectWise ScreenConnect to its Known Exploited Vulnerabilities (KEV) catalog, signaling that threat actors are actively targeting these products.

The KEV catalog serves as a curated list of software flaws that have been observed in the wild, providing federal and private entities with a prioritized set of patches and mitigations. By flagging an issue in the catalog, CISA indicates that exploitation is confirmed or highly probable, prompting immediate attention from organizations that rely on the affected software.

GitLab, a widely used platform for source‑code management and continuous integration, JFrog Artifactory, a repository manager for binary artifacts, and ConnectWise ScreenConnect, a remote support and desktop‑sharing tool, each occupy critical roles in modern development and IT operations. Their prevalence across enterprises makes any security weakness a potential vector for broader compromise.

While CISA’s notice does not disclose specific technical details, the inclusion of these products suggests that attackers could leverage the flaws to gain unauthorized access, execute arbitrary code, or move laterally within a network. Such capabilities align with recent trends where adversaries focus on supply‑chain and remote‑access tools to amplify impact.

Security teams are being urged to verify whether they run any of the listed versions and to apply vendor‑provided patches without delay. In cases where immediate remediation is not feasible, CISA recommends implementing temporary mitigations such as network segmentation, stricter access controls, and heightened monitoring for anomalous activity.

The move comes amid a surge in reported incidents involving development‑toolchains and remote‑access solutions, underscoring the expanding attack surface exposed by hybrid work models and accelerated software delivery pipelines.

Vendors have already acknowledged the findings and are expected to release or have released updates to address the vulnerabilities. CISA will continue to track exploitation activity and may issue further advisories or technical guidance as more information becomes available.

For organizations that depend on these platforms, the addition to the KEV catalog serves as a clear reminder that proactive vulnerability management remains a cornerstone of cyber resilience, especially as threat actors continue to hunt for high‑value footholds in critical infrastructure.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related