CISA Warns of Exploited SolarWinds Serv-U Vulnerability
ID: d99e91b2-8a86-5af3-a542-20dedb5385a9
STIX ID: report--d99e91b2-8a86-5af3-a542-20dedb5385a9
Feed Name: Cyber Press
Threat Score
**Executive summary:** CISA added CVE-2026-28318 — an unauthenticated uncontrolled resource consumption (DoS) flaw in SolarWinds Serv-U exploitable via a malformed HTTP POST with Content-Encoding:deflate — to its KEV catalog after confirming active targeting; SolarWinds released Serv-U 15.5.4 Hotfix 1, but thousands of internet-exposed instances remain vulnerable, so organizations should apply the hotfix, audit deployments, and implement WAF/proxy mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
