Find notable cyber news and cases, enriched with sources, timelines, and signals.

SolarWinds security patch release for CVE-2026-28318

Security Patch Release
First reported
Last updated
Happening score
H score 82
2 unique sources, 2 articles

Summary

Hide ▲

SolarWinds released Serv-U 15.5.4 Hotfix 1 for CVE-2026-28318, an actively exploited denial-of-service flaw that can crash exposed Serv-U servers. The update fixes an uncontrolled resource consumption weakness and covers the Windows and Linux file transfer product used for MFT and FTP services. Administrators that cannot patch immediately were told to restrict access and block POST requests containing content-encoding.

Related Happenings

CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)

Advisory/Mitigation
H score38 First: 16.06.2026 08:41 Last: 16.06.2026 08:41 Sources 1

About this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...

SolarWinds Serv-U advisory and mitigations for CVE-2026-28318

Advisory/Mitigation
H score52 First: 06.06.2026 11:14 Last: 06.06.2026 11:14 Sources 1

How related: While SolarWinds’s advisory makes no mention of CVE-2026-28318 being exploited in the wild, CISA on Friday added the bug to its Known Exploited Vulnerabilities (KEV) catalog.

About this happening: SolarWinds Serv-U mitigation guidance now covers CVE-2026-28318, reducing unauthenticated DoS risk from specially crafted POST requests. SolarWinds says the flaw is ad...

CISA KEV order for SolarWinds Serv-U CVE-2026-28318

Public Sector Action
H score50 First: 06.06.2026 11:14 Last: 06.06.2026 11:14 Sources 1

How related: In line with Binding Operational Directive (BOD) 22-01’s requirements, CISA urged federal agencies to patch the CVE by June 19 to keep their networks protected against active threats.

About this happening: CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...

Ivanti security patch release for CVE-2026-8043

Security Patch Release
H score25 First: 18.05.2026 13:54 Last: 18.05.2026 13:54 Sources 1

About this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...

CPanel security patch release for CVE-2026-29201

Security Patch Release
H score34 First: 09.05.2026 10:16 Last: 09.05.2026 10:16 Sources 1

About this happening: cPanel released updates for cPanel and Web Host Manager (WHM) to fix three vulnerabilities that could enable privilege escalation, code execution, or denial-...

Timeline

  1. 05.06.2026 22:15 3 articles · 1mo ago

    SolarWinds releases Serv-U 15.5.4 Hotfix 1 for CVE-2026-28318

    Mitigation Patch Update

    SolarWinds released Serv-U 15.5.4 Hotfix 1 for the Serv-U file transfer product to patch CVE-2026-28318, a denial-of-service flaw caused by an uncontrolled resource consumption weakness. The issue affects the Windows and Linux Serv-U service used for MFT and FTP capabilities, and the vendor advised administrators to install the hotfix or temporarily restrict access and block POST requests containing "content-encoding" if immediate patching is not possible.

    Show sources
  2. 05.06.2026 22:15 1 articles · 1mo ago

    CISA adds actively exploited Serv-U flaw CVE-2026-28318 to the KEV Catalog

    Legal Policy Action Update

    CISA warned that hackers are actively exploiting CVE-2026-28318 against Serv-U servers, added the flaw to the Known Exploited Vulnerabilities Catalog, and ordered Federal Civilian Executive Branch agencies to patch by June 19 under Binding Operational Directive 22-01. The agency also urged private-sector defenders to secure exposed networks as soon as possible.

    Show sources