logo

U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog

ID: 3e0595b4-952b-5d53-b07f-c95dbd8ed86b

STIX ID: report--3e0595b4-952b-5d53-b07f-c95dbd8ed86b

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-06-06

Date Updated: 2026-06-07

Author: Pierluigi Paganini

...
...

CISA added SolarWinds Serv‑U CVE‑2026‑28318 (CVSS 7.5) — an unauthenticated DoS triggered by specially crafted HTTP POST requests with Content-Encoding:deflate that crash the Serv‑U service — to its Known Exploited Vulnerabilities catalog. SolarWinds released fixes (Serv‑U 15.5.4 HF1) and mitigation guidance, and CISA directed federal agencies to remediate by June 19, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.