The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-28318, a SolarWinds Serv-U vulnerability allowing uncontrolled resource consumption, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Federal agencies are required to remediate the vulnerability by a specified deadline under Binding Operational Directive 22-01.