The story
— from one crafted request to a ransom noteOn 24 January 2024 a maximum-severity flaw in Jenkins — the automation server at the centre of tens of thousands of software build-and-deploy pipelines — became public as CVE-2024-238972. What follows is not really about one vulnerability. It is a clean, post-2021 measurement of how far the authoritative exploited-vulnerability list runs behind the reality it is meant to describe.
The mechanism is unglamorous and severe: the Jenkins command-line interface let an unauthenticated attacker read arbitrary files off the controller14 — and on a CI server those files are the crown jewels, the credentials and signing keys that reach every system it builds and ships. CISA records the severity as CVSS 9.83.
It did not stay theoretical. Public exploit code was catalogued within days6, exploitation was being reported from the field10, EPSS put the probability of exploitation at essentially one hundred percent5, and CISA later flagged it for known ransomware use4.
Here is the part that removes any doubt about awareness. In the machine-readable triage CISA publishes directly into the CVE record — its SSVC decision — CISA marked this flaw's exploitation status active and its automatability yes3. By CISA's own assessment, it was being actively and easily exploited.
And yet CISA's Known Exploited Vulnerabilities catalog — the list that sets binding federal patch deadlines, and that a great many defenders treat as the definitive record of what is being exploited — did not add CVE-2024-23897 until 19 August 20244: 208 days after it was published2. Two hundred and eight days in which it was public, weaponised, reported-exploited, and rated 'actively exploited' by CISA itself — but not yet on the list.
This is not an indictment of CISA; it is a measurement of a record-keeping system under strain. NVD, the enrichment authority, has by NIST's own statements fallen behind on analysing CVEs; the CVE programme itself nearly lost funding in 2024. The KEV catalog is a floor — the exploited flaws the government has confirmed and prioritised — not the ceiling of what is being exploited. Across the known-exploited records on this site, the gap between a CVE's publication and its KEV listing runs, at the median, to the better part of a year; the live figure sits in the currency panel on the front page. CVE-2024-23897 is one face of that gap — and the reason this site cites the vendor and the CVE record directly, rather than waiting for the authoritative catalogues to catch up.