ON June 5, 2026, CISA added a new vulnerability, CVE-2026-28318, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This vulnerability, associated with SolarWinds Serv-U, represents a significant risk to federal enterprises. Under Binding Operational Directive 22-01, FCEB agencies are required to remediate identified vulnerabilities to protect against cyber threats. CISA encourages all organizations to prioritize the timely remediation of vulnerabilities in the KEV Catalog.
CISA warns of active SolarWinds ServU exploit CVE-2026-28318
CyberSIXT Evidence Panel
Source marked as original reporting
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Critical flaw in SolarWinds ServU lets attackers drain resources
cybersixt.com
-
CISA warns of DoS risk in SolarWinds Serv-U flaw CVE-2026-28318
cybersixt.com
-
Attackers exploit CVE-2026-28318 and Zip Slip in Collibra Agent
cybersixt.com
-
Verizon VoLTE flaw CVE-2026-28318 exposes calls to interception
cybersixt.com
-
SolarWinds ServU bug lets attackers drain system resources
cybersixt.com
-
Cryptographic Sanctuaries: OpenAI Unveils “Lockdown Mode” to Counter Prompt Injection Risks
cybersixt.com
-
CISA flags SolarWinds ServU DoS bug CVE-2026-28318 for patch
cybersixt.com
-
CISA Adds Exploited SolarWinds ServU DoS Vulnerability to KEV List
cybersixt.com
-
CISA Warns of Actively Exploited SolarWinds Serv-U Flaw
cybersixt.com
-
CISA warns of exploited SolarWinds Serv-U flaw, urges patching
cybersixt.com
-
CISA adds CVE‑2026‑28318 to KEV after SolarWinds ServU attacks
cybersixt.com
-
CISA warns of active SolarWinds ServU exploit CVE-2026-28318
www.cisa.gov