Act
active
CISA KEV: 5 Active Exploits in Artifactory, ScreenConnect, RouterOS
- Engineer — Act: All five CVEs are KEV-listed with confirmed active exploitation; a public PoC exists for CVE-2026-42016 (CVSS 8.1). Audit your estate for JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS and apply vendor patches immediately — these are common CI/CD, remote-access, and network infrastructure components.
- SOC/IR — Act: Active exploitation of ScreenConnect (remote access) and Artifactory (build pipeline) creates high-value footholds; initiate assume-breach sweeps by reviewing ScreenConnect session logs and Artifactory access logs for unauthorized activity since the KEV listing date, and tune detections for anomalous authentication or file-access patterns on these systems.
- Leader — Plan: Confirm with engineering this week whether Artifactory, ScreenConnect, or RouterOS are deployed and verify an expedited patch cycle is underway; KEV listing raises the risk register for these assets but does not yet constitute a systemic breach event requiring board or customer notification.
- Signals: CVE-2026-42016 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.