U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog

2026-06-07T02:51:46Zb7aaac037722e80a0f050bb81a5afc58facdaaf13e72384457ea4d5580c908e6
AI securityAnthropicCISACVECiscoClaude OpusDNS fast-fluxGamaredonKnown Exploited VulnerabilitiesMirasvitMythosPCPJackSD-WANSSRFSilent Ransom GroupSolarWinds Serv-UUnified CMWinRARZcashcryptocurrencyemail relayprivilege escalationpublic PoCsupply chain

What happened

Feed summarizes multiple high-impact security developments: CISA added multiple Known Exploited Vulnerabilities (notably SolarWinds Serv-U CVE-2026-28318) and a critical Mirasvit cache-warmer flaw (CVE-2026-45247, CVSS 9.3). Cisco products have serious issues — an authenticated local-to-root file-upload/command-injection in SD‑WAN Manager (CVE-2026-20245) and a remotely exploytable SSRF in Unified CM with public PoC (CVE-2026-20230). Other coverage includes a critical, four-year Zcash Orchard privacy bug discovered using Claude Opus; Silent Ransom Group moving to DNS fast‑flux infrastructure;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
b7aaac037722e80a0f050bb81a5afc58facdaaf13e72384457ea4d5580c908e6
Enrichment time
2026-06-07T02:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog · Baitaphish