CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)
ID: e4bc31f8-26dc-5d4f-877b-2c6d298f82e5
STIX ID: report--e4bc31f8-26dc-5d4f-877b-2c6d298f82e5
Feed Name: Help Net Security
CISA warned that CVE-2026-28318, an unauthenticated resource-consumption vulnerability in SolarWinds Serv-U triggered by POST requests with Content-Encoding: deflate, is being exploited in the wild; SolarWinds released Serv-U 15.5.4 Hotfix 1 to address it and CISA ordered federal agencies to remediate by June 19, 2026. Organizations are advised to apply the hotfix or mitigate via web application firewalls and access restrictions because the flaw can crash Serv-U servers and cause denial-of-service, potentially disrupting operations in regulated sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
