CISA Flags Active Exploitation of JFrog Artifactory and ConnectWise ScreenConnect Flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. Two of the flaws affect JFrog Artifactory, a widely used software repository management tool, and involve incorrect authorization and improper authentication issues. The third affects ConnectWise ScreenConnect, a popular remote support and remote access tool, and involves improper privilege management and missing authorization controls.
While the directive requiring rapid remediation applies only to US federal agencies, CISA is urging all organisations, including businesses outside government, to treat KEV-listed vulnerabilities as high priority. Tools like ScreenConnect are commonly used by managed service providers and IT support teams, meaning Australian businesses using remote access software or software repositories should check whether they are running affected versions.
Exploited vulnerabilities in remote access and software management tools are attractive to attackers because they can provide broad control over systems and networks. Businesses relying on these platforms, directly or through a third-party IT provider, should confirm patching status as a priority.