CuraSec

Act active

CISA KEV: 5 Active Exploits in Artifactory, ScreenConnect, RouterOS

  • Engineer — Act: All five CVEs are KEV-listed with confirmed active exploitation; a public PoC exists for CVE-2026-42016 (CVSS 8.1). Audit your estate for JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS and apply vendor patches immediately — these are common CI/CD, remote-access, and network infrastructure components.
  • SOC/IR — Act: Active exploitation of ScreenConnect (remote access) and Artifactory (build pipeline) creates high-value footholds; initiate assume-breach sweeps by reviewing ScreenConnect session logs and Artifactory access logs for unauthorized activity since the KEV listing date, and tune detections for anomalous authentication or file-access patterns on these systems.
  • Leader — Plan: Confirm with engineering this week whether Artifactory, ScreenConnect, or RouterOS are deployed and verify an expedited patch cycle is underway; KEV listing raises the risk register for these assets but does not yet constitute a systemic breach event requiring board or customer notification.
  • Signals: CVE-2026-42016 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.