U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog
2026-06-07T02:51:46Z•b7aaac037722e80a0f050bb81a5afc58facdaaf13e72384457ea4d5580c908e6
AI securityAnthropicCISACVECiscoClaude OpusDNS fast-fluxGamaredonKnown Exploited VulnerabilitiesMirasvitMythosPCPJackSD-WANSSRFSilent Ransom GroupSolarWinds Serv-UUnified CMWinRARZcashcryptocurrencyemail relayprivilege escalationpublic PoCsupply chain
What happened
Feed summarizes multiple high-impact security developments: CISA added multiple Known Exploited Vulnerabilities (notably SolarWinds Serv-U CVE-2026-28318) and a critical Mirasvit cache-warmer flaw (CVE-2026-45247, CVSS 9.3). Cisco products have serious issues — an authenticated local-to-root file-upload/command-injection in SD‑WAN Manager (CVE-2026-20245) and a remotely exploytable SSRF in Unified CM with public PoC (CVE-2026-20230). Other coverage includes a critical, four-year Zcash Orchard privacy bug discovered using Claude Opus; Silent Ransom Group moving to DNS fast‑flux infrastructure;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- b7aaac037722e80a0f050bb81a5afc58facdaaf13e72384457ea4d5580c908e6
- Enrichment time
- 2026-06-07T02:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.