logo

CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers

ID: 01452314-545d-5b12-a2ec-47866cc56657

STIX ID: report--01452314-545d-5b12-a2ec-47866cc56657

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Sergiu Gatlan

...
...

CISA warns that a newly patched high-severity SolarWinds Serv-U vulnerability (CVE-2026-28318) is being actively exploited to crash Serv-U servers via specially crafted POST requests using Content-Encoding:deflate; SolarWinds released Serv-U 15.5.4 Hotfix 1, CISA added the flaw to its Known Exploited Vulnerabilities catalog, and federal agencies were ordered to patch immediately while defenders are urged to block or limit access until mitigations are deployed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.