logo

CISA Warns of Exploited SolarWinds Serv-U Vulnerability

ID: d99e91b2-8a86-5af3-a542-20dedb5385a9

STIX ID: report--d99e91b2-8a86-5af3-a542-20dedb5385a9

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-06-06

Date Updated: 2026-06-06

Author: Lucas Martin

...
...

**Executive summary:** CISA added CVE-2026-28318 — an unauthenticated uncontrolled resource consumption (DoS) flaw in SolarWinds Serv-U exploitable via a malformed HTTP POST with Content-Encoding:deflate — to its KEV catalog after confirming active targeting; SolarWinds released Serv-U 15.5.4 Hotfix 1, but thousands of internet-exposed instances remain vulnerable, so organizations should apply the hotfix, audit deployments, and implement WAF/proxy mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.