High severity7.5CISA KEVNVD Advisory· Published Jun 4, 2026· Updated Jun 5, 2026
CVE-2026-28318
CVE-2026-28318
Description
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*range: <15.5.4
- cpe:2.3:a:solarwinds:serv-u:15.5.4:-:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
3- www.solarwinds.com/trust-center/security-advisories/CVE-2026-28318nvdVendor Advisory
- documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4-hotfix-1_release_notes.htmnvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
9- Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attackHelp Net Security · Jun 14, 2026
- 8th June – Threat Intelligence ReportCheck Point Research · Jun 8, 2026
- ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and MoreThe Hacker News · Jun 8, 2026
- CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)Help Net Security · Jun 8, 2026
- SolarWinds Serv-U Vulnerability Exploited in the WildSecurityWeek · Jun 8, 2026
- CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV CatalogThe Hacker News · Jun 6, 2026
- CISA Warns of SolarWinds Serv-U Vulnerability Exploited in AttacksCyber Security News · Jun 6, 2026
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · Jun 5, 2026
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts