Back to Feed
VulnerabilitiesJun 5, 2026

RT @CISACyber: 🛡️ We added SolarWinds Serv-U uncontrolled resource consumption vulnerability CVE...

CISA adds SolarWinds Serv-U uncontrolled resource consumption CVE-2026-28318 to KEV catalog

Vendor Watch

Run SolarWinds?

Get an email when a reviewed story names SolarWinds, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

CISA has added CVE-2026-28318, an uncontrolled resource consumption vulnerability in SolarWinds Serv-U, to its Known Exploited Vulnerabilities (KEV) catalog. This designation indicates the flaw is being actively exploited in the wild and warrants immediate patching. Organizations using Serv-U should prioritize remediation.

Indicators of Compromise

  • cve — CVE-2026-28318

Entities

SolarWinds (vendor)Serv-U (product)CISA (vendor)