February 27, 2023 · Applied Cybernetics Group
CVE-2022-36537 — ZK Framework AuUploader
known ransomware use
ZK Framework AuUploader Unspecified Vulnerability
- Added to KEV
2023-02-27- Federal due date
2023-03-20- Vendor
- ZK Framework
- Product
- AuUploader
- EPSS
- 99.9th percentile (score 0.939, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-36537
CISA short description
ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.
Required action
Apply updates per vendor instructions.