All KEV additions

CISA KEV digest

CISA KEV 05 Jun 2026: 1 exploited flaw in SolarWinds

1 vulnerability
Conceptual illustration: A database cylinder and enterprise-application blocks, with a lime patch plate sealing a fractured access gateway. Headline: ENTERPRISE SECURITY.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

On 5 June 2026, CISA added 1 actively exploited vulnerability affecting SolarWinds to its Known Exploited Vulnerabilities catalog. If you run any of these products, patch or mitigate now — exploitation is already happening.

CVE-2026-28318Federal deadline

In this section

SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

SolarWinds / Serv-U / CWE-400

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.