EXPOSURES › CVE-2022-36537
CVE-2022-36537
CRITICAL ⌖ ON CISA KEV · EXPLOITEDZK Framework AuUploader servlets allow attackers to read arbitrary files in the web context, impacting products like ConnectWise R1Soft Server Backup Manager.
This file-read vulnerability enables attackers to exfiltrate sensitive data from systems using the ZK Framework, including backup managers. DIB organizations must verify their software supply chain for unpatched, actively exploited flaws like this one, which is now KEV and ransomware-linked. Immediate patching and supply-chain risk assessments are required to prevent data breaches and compliance failures.
Shame score — An open-source framework shipped with an unpatched, actively exploited vulnerability that attackers used for ransomware, demonstrating severe negligence in maintaining critical infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.