logo

CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks

ID: 5ea243c2-2f3a-5cf7-8f50-ed7fb69f038e

STIX ID: report--5ea243c2-2f3a-5cf7-8f50-ed7fb69f038e

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-06

Date Updated: 2026-06-06

Author: Guru Baran

...
...

CISA added CVE-2026-28318 — an Uncontrolled Resource Consumption (CWE-400) flaw in SolarWinds Serv-U that allows unauthenticated remote attackers to crash the service via specially crafted POST requests with a Content-Encoding:deflate header — to its Known Exploited Vulnerabilities catalog; SolarWinds has released Serv-U 15.5.4 Hotfix 1 and organizations are urged to apply the patch, restrict exposure, monitor for anomalous POST requests, or disable unpatched instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.