CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

A new wave of high-severity vulnerabilities has been added to the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog, with five fresh entries for Artifactory, ScreenConnect, and RouterOS. These flaws have been actively exploited in the wild, putting countless organizations at risk of cyber attacks.

The KEV catalog is a critical resource for IT teams and security professionals, as it highlights vulnerabilities that are being actively targeted by hackers. By prioritizing these vulnerabilities, organizations can take proactive measures to patch their systems and prevent breaches. In this case, the five newly added flaws have been linked to identity exposure, which can be used as an entry point for attackers.

The affected products include Artifactory, a popular software repository manager developed by JFrog; ScreenConnect, a remote desktop protocol (RDP) management tool; and RouterOS, a firmware-based operating system for network routers. The vulnerabilities in these systems allow attackers to gain elevated privileges, move laterally within an organization’s network, or even escape the compromised environment altogether.

To understand how this works, imagine a scenario where an attacker gains access to a user’s credentials through phishing or other means. With that information, they can then use identity exposure to map cross-domain privilege escalation and find weak points in the system. This allows them to move undetected within the network, exploiting vulnerabilities at key chokepoints to gain deeper access.

The inclusion of these five new vulnerabilities in the KEV catalog underscores the importance of proactive security measures. Organizations must ensure that their systems are patched regularly, particularly those with critical roles like authentication and authorization. Furthermore, IT teams should conduct regular vulnerability assessments to identify potential entry points for attackers.

As we’ve seen time and again, it’s not a matter of if but when an organization will be targeted by cyber attacks. The key is to have the right tools and strategies in place to detect and respond quickly. By prioritizing these high-severity vulnerabilities and taking proactive steps to secure their systems, organizations can reduce the risk of costly breaches and minimize the impact on their operations.

In practical terms, this means that IT teams should review the KEV catalog regularly to ensure they’re aware of any new threats. They should also conduct regular vulnerability assessments and prioritize patching efforts accordingly. Additionally, implementing robust security controls like multi-factor authentication and access controls can help prevent identity exposure from being exploited by attackers. By staying vigilant and proactive, organizations can reduce their risk profile and stay ahead of the evolving threat landscape.


Source: The Hacker News — 2026-09-12