The Latest KEV Additions: What You Need to Know

According to a report from The Hacker News, the U.S. Cybersecurity and Infrastructure Security Agency has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These flaws affect JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS — all tools that some Australian businesses may use for software development, remote support, or network equipment.

What makes this announcement significant is that attackers are already using these weaknesses in real-world attacks. When CISA adds a flaw to the KEV list, it signals that federal agencies must patch quickly. For Australian small and mid-sized businesses, this should also serve as a warning: cybercriminals don't respect borders, and they are actively scanning for unpatched systems here as well.

Why These Vulnerabilities Deserve Your Attention

The three product categories hit in this update cover very different areas of IT operations. JFrog Artifactory is used to manage software packages and code. ConnectWise ScreenConnect is a remote desktop tool common in managed service providers. MikroTik RouterOS runs on routers and switches used by many smaller offices.

What ties them together is the speed of exploitation. Attackers are chaining multiple bugs together — for example, using one flaw to bypass login checks and another to gain full administrative control. This means a single unpatched tool can become a gateway for deeper network compromise. The technical details are complex, but the bottom line is simple: these are not hypothetical risks; they are being used right now.

What This Means for Australian SMBs

Australian small and mid-sized businesses often rely on the same software stacks as larger enterprises, but with fewer dedicated security staff. If your company uses any of these tools — especially ScreenConnect for remote support or MikroTik routers for branch offices — you are a potential target. Attackers know that smaller teams may not patch quickly, and they actively search for exposed instances.

Beyond the immediate risk, these KEV additions highlight a broader trend: vulnerabilities in widely used commercial products are being exploited faster than ever. For Australian SMBs, this means waiting for a monthly patch cycle is no longer enough. You need a process to review security advisories and apply critical updates within days, not weeks.

What You Can Do Now

  • Check if your organisation uses JFrog Artifactory, ConnectWise ScreenConnect, or MikroTik RouterOS. Identify all versions currently in use.
  • Apply the latest patches from each vendor immediately. For ScreenConnect, update to version 26.6.5 or later. For MikroTik and Artifactory, follow the vendor’s specific guidance.
  • Review remote access policies. Disable anonymous access on Artifactory, require host confirmation for ScreenConnect sessions, and restrict SSH access on MikroTik routers to trusted IPs only.
  • Implement a vulnerability management routine. Use a simple checklist or a managed service to track CISA KEV additions and other critical alerts.
  • Conduct a quick network scan to see if any of these services are exposed to the internet. If they are, consider moving them behind a VPN or access control list.

MS&VG helps Australian SMBs stay ahead of threats like these with practical, no-nonsense cybersecurity advice and support. If you’re unsure where to start, we can help you assess your exposure and prioritise patches.