CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vuln...
Researched and edited by Kiran Ch and the WhatIsFuture editorial team. Reviewed for factual accuracy before publication.
If you are building complex software, managing cloud pipelines, or keeping corporate network perimeters intact, your security backlog probably feels like a relentless game of whack-a-mole. I know the feeling. The threat landscape has completely shifted from opportunistic script kiddies targeting random IP blocks to highly organized, systematic adversaries looking for structural leverage. When a vulnerability lands on your desk today, it is rarely a isolated bug; it is a potential key to the entire kingdom.
Recently, the Cybersecurity and Infrastructure Security Agency (CISA) added five critically dangerous, actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These flaws affect three ubiquitous components of modern enterprise IT infrastructure: JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. In my view, this specific batch of additions is a masterclass in how modern threat actors select their targets. They aren't just looking for open windows; they are targeting the master key generation systems, the remote access tunnels, and the backbone networking hardware that keeps businesses running.
Join Our Tech Community
Get instant alerts on the most critical AI breakthroughs on our WhatsApp channel. No spam, just signal.
I want to break down what these five vulnerabilities mean, why this combination of software is so deadly in the hands of sophisticated attackers, and what you need to do right now to ensure your environment isn't compromised.
The Shift Toward Structural Leverage in Cyber Attacks
In my research and discussions across the cybersecurity space at WhatIsFuture.com, I frequently emphasize a concept I call structural leverage. Threat actors have realized that compromising an individual end-user workstation yields minimal return on investment. Instead, if an attacker can compromise a central artifact repository like JFrog Artifactory, a remote management console like ConnectWise ScreenConnect, or edge routing firmware like MikroTik RouterOS, they gain access to hundreds—if not thousands—of downstream systems simultaneously.
Consider the strategic value of these target classes:
- Developer Build Tools & Repositories: Compromising a tool like Artifactory allows attackers to inject malicious code into production software pipelines, poisoning the software supply chain at its origin.
- Remote Monitoring & Management (RMM): Remote desktop tools like ScreenConnect grant native, highly privileged administrative access directly into internal networks, bypassing perimeter firewalls entirely.
- Edge Network Infrastructure: Exploiting edge devices like MikroTik routers gives threat actors persistent, unmonitored footholds for traffic interception, lateral movement, and botnet construction.
When CISA flags flaws in these technologies as actively exploited in the wild, it means state-sponsored groups or ransomware syndicates are already using these exact vectors to breach organizations. Let's dive deep into the five specific vulnerabilities that made the list.
Deconstructing the 5 Newly Added KEV Flaws
1. ConnectWise ScreenConnect Authentication Bypass (CVE-2024-1709)
In my opinion, this is one of the most severe flaws we have seen in recent years. CVE-2024-1709 represents a maximum-severity (CVSS 10.0) authentication bypass vulnerability in ConnectWise ScreenConnect. It allows an unauthenticated, remote attacker to access the initial setup wizard on an already-configured server. By re-running this setup routine, an attacker can create an administrative account, overwrite existing administrator configurations, and gain total operational control over the management console.
Once an attacker becomes an administrator on a ScreenConnect instance, it is game over. They can push malicious scripts, execute arbitrary code, and deploy ransomware directly to every connected endpoint across the entire organization or managed service provider (MSP) client base.
2. ConnectWise ScreenConnect Path Traversal (CVE-2024-1708)
Closely paired with the authentication bypass is CVE-2024-1708, a high-severity path traversal vulnerability within ScreenConnect. This flaw allows an authenticated attacker (or an attacker who has just bypassed authentication using CVE-2024-1709) to write arbitrary files outside the intended web root directory on the host server.
When combined, these two vulnerabilities form an extraordinarily reliable exploit chain. Threat actors leverage CVE-2024-1709 to gain admin access and then immediately utilize CVE-2024-1708 to drop web shells or custom malware binaries directly onto the host operating system. I have watched ransomware gangs like LockBit and BlackBasta abuse this exact combination within hours of proof-of-concept code becoming public.
3. JFrog Artifactory Arbitrary File Generation (CVE-2022-41352)
JFrog Artifactory is the beating heart of DevOps pipelines in thousands of enterprises, storing binary artifacts, Docker images, and dependencies. CVE-2022-41352 stems from an unsafe archive extraction mechanism (often referred to generically as a Zip Slip style flaw). When Artifactory processes a specially crafted archive file, it fails to properly sanitize file extraction paths.
This allows a remote attacker to write arbitrary files to any location on the underlying server's filesystem where the process has permission. In practical terms, an attacker can overwrite critical system binaries, inject malicious configuration files, or drop a persistent backdoor directly into the build pipeline infrastructure. From my perspective, supply chain attacks leveraging DevOps repository flaws are among the hardest to detect because security operations teams rarely monitor build server file structures with the same rigor as production databases.
4. MikroTik RouterOS Privilege Escalation (CVE-2023-30799)
Network routers are the silent workhorses of internet infrastructure, and MikroTik’s RouterOS powers millions of deployment scenarios worldwide. CVE-2023-30799 is a critical privilege escalation vulnerability in RouterOS. It enables an attacker with existing low-privileged administrative access (such as credentials obtained through password spraying or default settings) to escalate their privileges to full root-level control via the system's WinBox or HTTP interfaces.
While some might argue that requiring initial credentials lowers the risk, my observation is that weak or recycled credentials on edge network devices remain rampant. Once an attacker gains root access on a MikroTik router, they can patch the kernel, redirect network traffic, capture sensitive operational data, or turn the hardware into a node for massive distributed denial-of-service (DDoS) botnets like Meris.
5. MikroTik RouterOS Buffer Overflow (CVE-2023-32154)
The second RouterOS vulnerability added to the KEV catalog, CVE-2023-32154, involves a memory corruption issue within the handling of network advertisements (specifically surrounding IPv6 routing protocols or DNS processing depending on the service build). An unauthenticated attacker on the local network segment or capable of injecting crafted packets can trigger a buffer overflow.
This vulnerability allows for remote code execution directly on the router's architecture. Because network hardware operates beneath the visibility layer of standard Endpoint Detection and Response (EDR) software, compromised routers can host covert command-and-control (C2) infrastructure for months without triggering a single security alert.
Why Modern Infrastructure Management Demands a Priority Reset
When CISA updates the KEV catalog, it sends a clear signal: stop worrying about theoretical risks on internal subnets and fix these active enterprise entry points immediately. Federal agencies are mandated under Binding Operational Directive (BOD) 22-01 to patch these vulnerabilities within strict deadlines, but in my view, private sector teams should treat these notices with equal urgency.
"CVSS scores tell you how severe a vulnerability could be in a lab; the CISA KEV catalog tells you which vulnerabilities are currently tearing through real-world corporate networks."
In my opinion, too many organizations rely solely on raw CVSS scores when prioritizing patches. A CVSS 9.8 vulnerability in an isolated testing environment is significantly less dangerous than a CVSS 8.8 flaw in a publicly accessible edge router that is being actively exploited by advanced persistent threat (APT) groups. The inclusion of these five flaws in the KEV list is definitive proof that real-world attackers are prioritizing access to build tools, management utilities, and network perimeters.
Actionable Blueprint: How to Secure Your Environment
If you suspect or know that you run ScreenConnect, JFrog Artifactory, or MikroTik RouterOS in your infrastructure, here is my recommended immediate response plan:
Step 1: Emergency Auditing and Inventory Isolation
Identify every instance of these products across your enterprise—including cloud environments, branch offices, and shadow IT setups. Temporarily restrict access to administrative portals (such as ScreenConnect web interfaces or RouterOS WinBox services) so they are accessible only via a secure, zero-trust network access (ZTNA) tunnel or trusted VPN.
Step 2: Patch and Upgrade Immediately
Apply the official vendor patches without delay:
- ConnectWise ScreenConnect: Upgrade to version 23.9.8 or higher immediately. If you are using on-premises ScreenConnect, verify that no unauthorized user accounts were created prior to applying the patch.
- JFrog Artifactory: Patch to the latest maintenance release and audit system directories for unexpected or modified files dropped via archive imports.
- MikroTik RouterOS: Update all devices to the stable RouterOS release (version 7.x branch) and disable unnecessary management protocols facing the public internet.
Step 3: Conduct Threat Hunting for Indicators of Compromise (IoCs)
Applying a patch does not evict an attacker who has already breached your system. You must assume compromise if these services were exposed to the internet while vulnerable:
- Check ScreenConnect logs for unauthorized account creation, specifically inspecting the
User.xmlconfiguration file. - Inspect Artifactory deployment logs for unusual archive uploads and verify the integrity of published software artifacts.
- Review RouterOS user databases, system scripts, and scheduled tasks for persistent backdoors or unauthorized DNS/proxy redirections.
My Final Thoughts
Securing modern enterprise architecture requires us to accept a uncomfortable reality: the software management tools and network infrastructure we rely on to control our environments are primary targets for our enemies. The addition of these five Artifactory, ScreenConnect, and RouterOS flaws to CISA's KEV catalog isn't just routine news—it is a urgent wake-up call to audit our attack surfaces, prioritize threat intelligence over theoretical scores, and harden the structural foundation of our digital networks.
Frequently Asked Questions
Why should non-governmental companies follow CISA's KEV catalog?
While CISA directives legally bind only federal civilian agencies, the KEV catalog is widely considered the single most reliable source of real-world threat intelligence. It filters out tens of thousands of theoretical vulnerabilities to focus exclusively on bugs that attackers are actively exploiting in real attacks right now. Using KEV ensures your team prioritizes real threats over laboratory risks.
How does a flaw in a dev tool like JFrog Artifactory impact non-developers?
If an attacker compromises an artifact repository like JFrog Artifactory, they can tamper with software builds and dependencies. This allows them to insert hidden backdoors or malicious code into internal enterprise applications or customer-facing products. The impact spreads far beyond dev teams, potentially leading to company-wide data breaches, ransomware deployment, or software supply chain compromises for your downstream customers.
What should I do if my ScreenConnect server was exposed before I could patch CVE-2024-1709?
Because exploitation of CVE-2024-1709 takes seconds and yields full admin access, you must treat an unpatched, internet-exposed server as fully compromised. Immediately isolate the host from the network, review user account logs for newly created administrative profiles, check for unauthorized local scripts or web shells, restore system binaries from a known clean backup, and update to the latest patched version before reconnecting the server.
This analysis was inspired by a story originally reported by The Hacker News. Read the original report →
Supercharge Your Workflow with Claude AI
The AI assistant used by professionals worldwide. Write, code, analyse — all in one place.



