CISA Adds One Known Exploited Vulnerability to Catalog
CISA added one new vulnerability to its Known Exploited Vulnerabilities Catalog after finding active exploitation: CVE-2026-28318 in SolarWinds Serv-U.
Intelligence analysis by GPT-5.4 Mini
CISA says it has added CVE-2026-28318, a SolarWinds Serv-U uncontrolled resource consumption flaw, to its KEV Catalog because it is being actively exploited. The agency again urges timely remediation, especially for federal civilian agencies.
CISA is like a safety crew that keeps a list of broken locks that thieves are already using. It just added one more bad lock in SolarWinds Serv-U, so computer teams should fix it quickly before more damage happens.
Analysis
What CISA added
CISA says it added one new item to its Known Exploited Vulnerabilities Catalog on June 5, 2026: CVE-2026-28318, described as a SolarWinds Serv-U uncontrolled resource consumption vulnerability. The agency says the decision is based on evidence of active exploitation.
Why the catalog matters
The KEV Catalog is a living list of vulnerabilities that CISA considers especially dangerous because they are known to be used by attackers. The alert points to Binding Operational Directive 22-01, which requires Federal Civilian Executive Branch agencies to remediate listed vulnerabilities by the due date.
What organizations should take from this
CISA says this type of flaw is a frequent attack vector and poses significant risk to the federal enterprise. While the binding directive applies only to FCEB agencies, CISA strongly urges all organizations to prioritize timely remediation of KEV Catalog items as part of normal vulnerability management.
Practical takeaway
The alert is short and operational: the important part is not a long technical analysis, but the fact that a real-world exploited vulnerability has been identified and added to the list. For defenders, that means this should move near the top of patching and exposure review queues, especially where SolarWinds Serv-U is in use.
Key points
- CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities Catalog on June 5, 2026.
- The flaw is in SolarWinds Serv-U and is described as an uncontrolled resource consumption vulnerability.
- CISA says there is evidence of active exploitation.
- Federal civilian agencies must remediate KEV-listed vulnerabilities under BOD 22-01.
- CISA urges all organizations to prioritize KEV items in their vulnerability management process.
If organizations follow CISA's guidance, they can reduce exposure to an actively exploited flaw before it spreads further. Federal agencies also have a clear remediation requirement under BOD 22-01, which can speed up response.
If teams delay action, attackers may continue to use the flaw against exposed systems. Because CISA says the vulnerability is already being exploited, unpatched environments face immediate risk rather than a hypothetical future threat.



