logo

CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)

ID: e4bc31f8-26dc-5d4f-877b-2c6d298f82e5

STIX ID: report--e4bc31f8-26dc-5d4f-877b-2c6d298f82e5

Feed Name: Help Net Security

Threat Score
65/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Zeljka Zorz

...
...

CISA warned that CVE-2026-28318, an unauthenticated resource-consumption vulnerability in SolarWinds Serv-U triggered by POST requests with Content-Encoding: deflate, is being exploited in the wild; SolarWinds released Serv-U 15.5.4 Hotfix 1 to address it and CISA ordered federal agencies to remediate by June 19, 2026. Organizations are advised to apply the hotfix or mitigate via web application firewalls and access restrictions because the flaw can crash Serv-U servers and cause denial-of-service, potentially disrupting operations in regulated sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.