Bottom line: CISA has added 5 vulnerabilities to its KEV catalog, impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.
What's happening: JFrog Artifactory CVE-2021-22892 has a CVSS score of 9.8, allowing an attacker to execute arbitrary code on the server. ConnectWise ScreenConnect CVE-2022-30563 has a CVSS score of 7.8, allowing an attacker to bypass authentication. MikroTik RouterOS CVE-2022-3544 has a CVSS score of 9.5, allowing an attacker to execute arbitrary code on the device. These vulnerabilities were reported to be actively exploited in the wild.
What to do: Security leaders should prioritize patching these vulnerabilities in their environments and monitor for signs of exploitation. MikroTik RouterOS devices are particularly vulnerable due to the high CVSS score, and JFrog Artifactory users should also take immediate action to patch the vulnerability.