SolarWinds Serv-U denial-of-service flaw actively exploited (CVE-2026-28318)
Vulnerability
Summary
Hide ▲
Show ▼
CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. The high-severity flaw is a denial-of-service (DoS) issue in SolarWinds Serv-U multi-protocol file server software that can be triggered by specially crafted POST requests using `Content-Encoding: deflate` to crash the service without authentication. SolarWinds says the bug is fixed in Serv-U 15.5.4 HF1, and administrators are advised to limit access to known addresses and block requests containing "content-encoding" until patching is complete. FCEB agencies must remediate by June 19, 2026 under BOD 22-01.
Related Happenings
SolarWinds Serv-U advisory and mitigations for CVE-2026-28318
Advisory/Mitigation
H score52
First: 06.06.2026 11:14
Last: 06.06.2026 11:14
Sources 1
How related:
The issue has been addressed in SolarWinds Serv-U version 15.5.4 HF1. As mitigations, it's advised to limit access to known addresses and block any request containing "content-encoding" since the vulnerable service does not require this functionality.
About this happening:
SolarWinds Serv-U mitigation guidance now covers CVE-2026-28318, reducing unauthenticated DoS risk from specially crafted POST requests. SolarWinds says the flaw is ad...
SolarWinds Serv-U advisory and mitigations for CVE-2026-28318
Advisory/MitigationHow related: The issue has been addressed in SolarWinds Serv-U version 15.5.4 HF1. As mitigations, it's advised to limit access to known addresses and block any request containing "content-encoding" since the vulnerable service does not require this functionality.
About this happening: SolarWinds Serv-U mitigation guidance now covers CVE-2026-28318, reducing unauthenticated DoS risk from specially crafted POST requests. SolarWinds says the flaw is ad...
CISA KEV order for SolarWinds Serv-U CVE-2026-28318
Public Sector Action
H score50
First: 06.06.2026 11:14
Last: 06.06.2026 11:14
Sources 1
How related:
In line with Binding Operational Directive (BOD) 22-01’s requirements, CISA urged federal agencies to patch the CVE by June 19 to keep their networks protected against active threats.
About this happening:
CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...
CISA KEV order for SolarWinds Serv-U CVE-2026-28318
Public Sector ActionHow related: In line with Binding Operational Directive (BOD) 22-01’s requirements, CISA urged federal agencies to patch the CVE by June 19 to keep their networks protected against active threats.
About this happening: CISA added CVE-2026-28318 affecting SolarWinds Serv-U to the KEV catalog and ordered FCEB agencies to remediate it by June 19, 2026. The directive expands...
CISA orders FCEB remediation deadlines for KEV vulnerabilities
Public Sector Action
H score38
First: 10.03.2026 08:17
Last: 10.03.2026 08:17
Sources 1
About this happening:
CISA ordered FCEB agencies to patch SolarWinds Web Help Desk by March 12, 2026 and to fix the other two KEV-listed flaws by March 23, 2026, tightening remediation...
CISA orders FCEB remediation deadlines for KEV vulnerabilities
Public Sector ActionAbout this happening: CISA ordered FCEB agencies to patch SolarWinds Web Help Desk by March 12, 2026 and to fix the other two KEV-listed flaws by March 23, 2026, tightening remediation...
Serv-U broken access control RCE (CVE-2025-40538)
Vulnerability
H score56
First: 24.02.2026 15:00
Last: 24.02.2026 15:00
Sources 1
About this happening:
CVE-2025-40538 in SolarWinds Serv-U can let attackers with high privileges create a system admin user and execute code as root, putting unpatched servers at risk o...
Serv-U broken access control RCE (CVE-2025-40538)
VulnerabilityAbout this happening: CVE-2025-40538 in SolarWinds Serv-U can let attackers with high privileges create a system admin user and execute code as root, putting unpatched servers at risk o...
SolarWinds Web Help Desk (WHD) multi-stage exploitation wave
Exploitation Wave
H score44
First: 09.02.2026 16:42
Last: 09.02.2026 16:42
Sources 1
About this happening:
SolarWinds Web Help Desk (WHD) exploitation is a multi-stage intrusion wave affecting internet-exposed WHD instances. The foothold remains unconfirmed, but the wave is...
SolarWinds Web Help Desk (WHD) multi-stage exploitation wave
Exploitation WaveAbout this happening: SolarWinds Web Help Desk (WHD) exploitation is a multi-stage intrusion wave affecting internet-exposed WHD instances. The foothold remains unconfirmed, but the wave is...
Latest development: 10.03.2026 08:17
CISA added CVE-2025-26399 in SolarWinds Web Help Desk to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation, said Microsoft and Huntress had reported threat actors using SolarWinds Web Help Desk flaws to obtain initial access, attributed the activity to the Warlock ransomware crew, and ordered Federal Civilian Executive Branch (FCEB) agencies to apply the fix by March 12, 2026.
Timeline
-
05.06.2026 22:15 1 articles · 1mo ago
SolarWinds releases Serv-U 15.5.4 Hotfix 1 for CVE-2026-28318
Mitigation Patch UpdateSolarWinds released Serv-U 15.5.4 Hotfix 1 to patch the Serv-U denial-of-service flaw CVE-2026-28318, which stems from an uncontrolled resource consumption weakness and can be triggered by specially crafted POST requests using Content-Encoding: deflate.
Show sources
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers — www.bleepingcomputer.com — 05.06.2026 22:15
-
05.06.2026 22:15 3 articles · 1mo ago
CISA warns hackers are actively exploiting CVE-2026-28318 to crash Serv-U servers
Initial DisclosureCISA warned that hackers are actively exploiting the recently patched SolarWinds Serv-U flaw CVE-2026-28318 against exposed Serv-U servers, where unauthenticated attackers can use specially crafted POST requests with Content-Encoding: deflate to crash the Serv-U service.
Show sources
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers — www.bleepingcomputer.com — 05.06.2026 22:15
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers — www.bleepingcomputer.com — 05.06.2026 22:15
- SolarWinds Serv-U Vulnerability Exploited in the Wild — www.securityweek.com — 08.06.2026 10:52
-
05.06.2026 22:15 2 articles · 1mo ago
CISA adds CVE-2026-28318 to the KEV Catalog and orders patching by June 19
Legal Policy Action UpdateCISA added CVE-2026-28318 to the Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to patch Serv-U servers by June 19 under Binding Operational Directive 22-01, while also urging other defenders to secure exposed systems as soon as possible.
Show sources
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers — www.bleepingcomputer.com — 05.06.2026 22:15
- CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog — thehackernews.com — 06.06.2026 11:14