CISA Alerts on Actively Exploited SolarWinds Serv-U Denial-of-Service Flaw
ID: c5766d0d-c7a9-5aa2-857d-0652c85bdda0
STIX ID: report--c5766d0d-c7a9-5aa2-857d-0652c85bdda0
Feed Name: GBHackers
Threat Score
SolarWinds Serv-U (CVE-2026-28318) contains an uncontrolled resource consumption flaw (CWE-400) allowing unauthenticated remote actors to trigger a DoS via crafted POST requests with the Content-Encoding:deflate header; CISA added the CVE to its KEV catalog due to observed active exploitation, federal agencies are required to remediate under BOD 22-01, and SolarWinds has released a 15.5.4 Hotfix 1 patch with mitigations recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
