CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

Cybersecurity agencies have been sounding the alarm about a growing threat landscape, and the latest development from CISA only adds to the urgency. In a significant move, the Cybersecurity and Infrastructure Security Agency has added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, which includes flaws in Artifactory, ScreenConnect, and RouterOS software.

The KEV catalog is a critical resource for organizations seeking to stay ahead of emerging threats. By publishing these vulnerabilities, CISA is helping security teams prioritize their patching efforts and fortify their defenses against potential attacks. The five newly added flaws are: CVE-2022-2876 (Artifactory), CVE-2019-11506 (ScreenConnect), and three RouterOS vulnerabilities: CVE-2021-3063, CVE-2021-3064, and CVE-2021-3065.

To understand the significance of these flaws, let’s dive into how they work. A vulnerability is essentially a weakness in software that an attacker can exploit to gain unauthorized access or control. In this case, the vulnerabilities listed above are being actively exploited by malicious actors, which means attackers are using them to breach systems and cause harm. For instance, CVE-2022-2876 affects Artifactory, a popular package manager used by many organizations. If left unpatched, it can allow an attacker to extract sensitive data or even take control of the system.

The impact is far-reaching, with multiple sectors affected by these vulnerabilities. According to CISA, the flaws are being exploited in various industries, including finance, healthcare, and government. This highlights the importance of prioritizing security and keeping software up-to-date. Organizations that have not yet patched their systems are essentially leaving a door open for attackers to walk in.

The KEV catalog is an essential tool for security professionals, but it requires context to understand its significance. The catalog serves as a “watchlist” for vulnerabilities that are being actively exploited by malicious actors. By adding these five flaws to the list, CISA is effectively saying: “These vulnerabilities are being used by attackers right now, and you should patch them ASAP.” This warning is not just limited to security teams; it’s also a call to action for IT professionals, developers, and even non-technical staff who handle sensitive data.

In light of this development, organizations must take immediate action to protect themselves. The first step is to review the KEV catalog and identify any vulnerabilities that affect their systems or software. Next, they should prioritize patching these flaws as soon as possible. It’s also essential for security teams to stay vigilant and monitor their networks for signs of suspicious activity. By taking proactive measures, organizations can minimize the risk of a breach and protect sensitive data from falling into the wrong hands.

In conclusion, the addition of these five vulnerabilities to the KEV catalog serves as a stark reminder of the importance of cybersecurity in today’s threat landscape. Organizations must stay ahead of emerging threats by prioritizing patching efforts and keeping their software up-to-date. By doing so, they can reduce the risk of a breach and protect sensitive data from falling into the wrong hands.


Source: The Hacker News — 2026-09-12