SolarWinds security patch release for CVE-2026-28318
Security Patch Release
Summary
Hide ▲
Show ▼
SolarWinds released Serv-U 15.5.4 Hotfix 1 for CVE-2026-28318, an actively exploited denial-of-service flaw that can crash exposed Serv-U servers. The update fixes an uncontrolled resource consumption weakness and covers the Windows and Linux file transfer product used for MFT and FTP services. Administrators that cannot patch immediately were told to restrict access and block POST requests containing content-encoding.
Related Happenings
CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/Mitigation
H score38
First: 16.06.2026 08:41
Last: 16.06.2026 08:41
Sources 1
About this happening:
CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...
CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)
Advisory/MitigationAbout this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...
SolarWinds Serv-U advisory and mitigations for CVE-2026-28318
Advisory/Mitigation
H score52
First: 06.06.2026 11:14
Last: 06.06.2026 11:14
Sources 1
How related:
While SolarWinds’s advisory makes no mention of CVE-2026-28318 being exploited in the wild, CISA on Friday added the bug to its Known Exploited Vulnerabilities (KEV) catalog.
About this happening:
SolarWinds Serv-U mitigation guidance now covers CVE-2026-28318, reducing unauthenticated DoS risk from specially crafted POST requests. SolarWinds says the flaw is ad...
SolarWinds Serv-U advisory and mitigations for CVE-2026-28318
Advisory/MitigationHow related: While SolarWinds’s advisory makes no mention of CVE-2026-28318 being exploited in the wild, CISA on Friday added the bug to its Known Exploited Vulnerabilities (KEV) catalog.
About this happening: SolarWinds Serv-U mitigation guidance now covers CVE-2026-28318, reducing unauthenticated DoS risk from specially crafted POST requests. SolarWinds says the flaw is ad...
CISA KEV order for SolarWinds Serv-U CVE-2026-28318
Public Sector Action
H score50
First: 06.06.2026 11:14
Last: 06.06.2026 11:14
Sources 1
How related:
In line with Binding Operational Directive (BOD) 22-01’s requirements, CISA urged federal agencies to patch the CVE by June 19 to keep their networks protected against active threats.
About this happening:
CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...
CISA KEV order for SolarWinds Serv-U CVE-2026-28318
Public Sector ActionHow related: In line with Binding Operational Directive (BOD) 22-01’s requirements, CISA urged federal agencies to patch the CVE by June 19 to keep their networks protected against active threats.
About this happening: CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...
Ivanti security patch release for CVE-2026-8043
Security Patch Release
H score25
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
CPanel security patch release for CVE-2026-29201
Security Patch Release
H score34
First: 09.05.2026 10:16
Last: 09.05.2026 10:16
Sources 1
About this happening:
cPanel released updates for cPanel and Web Host Manager (WHM) to fix three vulnerabilities that could enable privilege escalation, code execution, or denial-...
CPanel security patch release for CVE-2026-29201
Security Patch ReleaseAbout this happening: cPanel released updates for cPanel and Web Host Manager (WHM) to fix three vulnerabilities that could enable privilege escalation, code execution, or denial-...
Timeline
-
05.06.2026 22:15 3 articles · 1mo ago
SolarWinds releases Serv-U 15.5.4 Hotfix 1 for CVE-2026-28318
Mitigation Patch UpdateSolarWinds released Serv-U 15.5.4 Hotfix 1 for the Serv-U file transfer product to patch CVE-2026-28318, a denial-of-service flaw caused by an uncontrolled resource consumption weakness. The issue affects the Windows and Linux Serv-U service used for MFT and FTP capabilities, and the vendor advised administrators to install the hotfix or temporarily restrict access and block POST requests containing "content-encoding" if immediate patching is not possible.
Show sources
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers — www.bleepingcomputer.com — 05.06.2026 22:15
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers — www.bleepingcomputer.com — 05.06.2026 22:15
- SolarWinds Serv-U Vulnerability Exploited in the Wild — www.securityweek.com — 08.06.2026 10:52
-
05.06.2026 22:15 1 articles · 1mo ago
CISA adds actively exploited Serv-U flaw CVE-2026-28318 to the KEV Catalog
Legal Policy Action UpdateCISA warned that hackers are actively exploiting CVE-2026-28318 against Serv-U servers, added the flaw to the Known Exploited Vulnerabilities Catalog, and ordered Federal Civilian Executive Branch agencies to patch by June 19 under Binding Operational Directive 22-01. The agency also urged private-sector defenders to secure exposed networks as soon as possible.
Show sources
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers — www.bleepingcomputer.com — 05.06.2026 22:15