Find notable cyber news and cases, enriched with sources, timelines, and signals.

SolarWinds Serv-U denial-of-service flaw actively exploited (CVE-2026-28318)

Vulnerability
First reported
Last updated
Happening score
H score 73
3 unique sources, 3 articles

Summary

Hide ▲

CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. The high-severity flaw is a denial-of-service (DoS) issue in SolarWinds Serv-U multi-protocol file server software that can be triggered by specially crafted POST requests using `Content-Encoding: deflate` to crash the service without authentication. SolarWinds says the bug is fixed in Serv-U 15.5.4 HF1, and administrators are advised to limit access to known addresses and block requests containing "content-encoding" until patching is complete. FCEB agencies must remediate by June 19, 2026 under BOD 22-01.

Related Happenings

SolarWinds Serv-U advisory and mitigations for CVE-2026-28318

Advisory/Mitigation
H score52 First: 06.06.2026 11:14 Last: 06.06.2026 11:14 Sources 1

How related: The issue has been addressed in SolarWinds Serv-U version 15.5.4 HF1. As mitigations, it's advised to limit access to known addresses and block any request containing "content-encoding" since the vulnerable service does not require this functionality.

About this happening: SolarWinds Serv-U mitigation guidance now covers CVE-2026-28318, reducing unauthenticated DoS risk from specially crafted POST requests. SolarWinds says the flaw is ad...

CISA KEV order for SolarWinds Serv-U CVE-2026-28318

Public Sector Action
H score50 First: 06.06.2026 11:14 Last: 06.06.2026 11:14 Sources 1

How related: In line with Binding Operational Directive (BOD) 22-01’s requirements, CISA urged federal agencies to patch the CVE by June 19 to keep their networks protected against active threats.

About this happening: CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...

CISA orders FCEB remediation deadlines for KEV vulnerabilities

Public Sector Action
H score38 First: 10.03.2026 08:17 Last: 10.03.2026 08:17 Sources 1

About this happening: CISA ordered FCEB agencies to patch SolarWinds Web Help Desk by March 12, 2026 and to fix the other two KEV-listed flaws by March 23, 2026, tightening remediation...

Serv-U broken access control RCE (CVE-2025-40538)

Vulnerability
H score56 First: 24.02.2026 15:00 Last: 24.02.2026 15:00 Sources 1

About this happening: CVE-2025-40538 in SolarWinds Serv-U can let attackers with high privileges create a system admin user and execute code as root, putting unpatched servers at risk o...

SolarWinds Web Help Desk (WHD) multi-stage exploitation wave

Exploitation Wave
H score44 First: 09.02.2026 16:42 Last: 09.02.2026 16:42 Sources 1

About this happening: SolarWinds Web Help Desk (WHD) exploitation is a multi-stage intrusion wave affecting internet-exposed WHD instances. The foothold remains unconfirmed, but the wave is...

Latest development: 10.03.2026 08:17

CISA added CVE-2025-26399 in SolarWinds Web Help Desk to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation, said Microsoft and Huntress had reported threat actors using SolarWinds Web Help Desk flaws to obtain initial access, attributed the activity to the Warlock ransomware crew, and ordered Federal Civilian Executive Branch (FCEB) agencies to apply the fix by March 12, 2026.

Timeline

  1. 05.06.2026 22:15 1 articles · 1mo ago

    SolarWinds releases Serv-U 15.5.4 Hotfix 1 for CVE-2026-28318

    Mitigation Patch Update

    SolarWinds released Serv-U 15.5.4 Hotfix 1 to patch the Serv-U denial-of-service flaw CVE-2026-28318, which stems from an uncontrolled resource consumption weakness and can be triggered by specially crafted POST requests using Content-Encoding: deflate.

    Show sources
  2. 05.06.2026 22:15 3 articles · 1mo ago

    CISA warns hackers are actively exploiting CVE-2026-28318 to crash Serv-U servers

    Initial Disclosure

    CISA warned that hackers are actively exploiting the recently patched SolarWinds Serv-U flaw CVE-2026-28318 against exposed Serv-U servers, where unauthenticated attackers can use specially crafted POST requests with Content-Encoding: deflate to crash the Serv-U service.

    Show sources
  3. 05.06.2026 22:15 2 articles · 1mo ago

    CISA adds CVE-2026-28318 to the KEV Catalog and orders patching by June 19

    Legal Policy Action Update

    CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to patch Serv-U servers by June 19 under Binding Operational Directive 22-01, while also urging other defenders to secure exposed systems as soon as possible.

    Show sources