Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AICISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
CISA has added a high-severity denial-of-service vulnerability (CVE-2026-28318) affecting SolarWinds Serv-U file server software to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation in the wild. The flaw, with a CVSS score of 7.5, can cause the service to crash, potentially disrupting critical file transfer operations for enterprise organizations.
AICISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
CISA has added CVE-2026-45247, a critical remote code execution vulnerability in Mirasvit Cache Warmer for Magento, to its Known Exploited Vulnerabilities catalog. The flaw, which has a CVSS score of 9.8, involves deserialization of untrusted data and is being actively exploited in the wild, posing significant risk to e-commerce platforms using this popular full-page cache extension.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added CVE-2026-42208, a SQL injection vulnerability in BerriAI LiteLLM, to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation. While remediation is mandatory for Federal Civilian Executive Branch agencies under BOD 22-01, CISA strongly recommends all organizations prioritize patching these vulnerabilities as part of their vulnerability management practices.
