logo

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

ID: 6cc04b81-9711-5e34-a268-38641a1d14d4

STIX ID: report--6cc04b81-9711-5e34-a268-38641a1d14d4

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-06-06

Date Updated: 2026-06-06

Author: [email protected] (The Hacker News)

...
...

CISA added a high-severity denial-of-service vulnerability in SolarWinds Serv-U (CVE-2026-28318, CVSS 7.5) to its Known Exploited Vulnerabilities catalog citing evidence of active exploitation; specially crafted unauthenticated POST requests using Content-Encoding:deflate can crash the Serv-U service. SolarWinds released a fix in Serv-U 15.5.4 HF1, and mitigations include restricting access and blocking requests containing content-encoding; CISA directed federal agencies to remediate by June 19, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.