CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vuln

Bottom line: CISA has added 5 vulnerabilities to its KEV catalog, impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.

What's happening: JFrog Artifactory CVE-2021-22892 has a CVSS score of 9.8, allowing an attacker to execute arbitrary code on the server. ConnectWise ScreenConnect CVE-2022-30563 has a CVSS score of 7.8, allowing an attacker to bypass authentication. MikroTik RouterOS CVE-2022-3544 has a CVSS score of 9.5, allowing an attacker to execute arbitrary code on the device. These vulnerabilities were reported to be actively exploited in the wild.

What to do: Security leaders should prioritize patching these vulnerabilities in their environments and monitor for signs of exploitation. MikroTik RouterOS devices are particularly vulnerable due to the high CVSS score, and JFrog Artifactory users should also take immediate action to patch the vulnerability.

Source: The Hacker News