CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks
Key Takeaways A critical vulnerability in SolarWinds Serv-U, tracked as CVE-2026-28318, is being actively exploited in the wild. The flaw allows unauthenticated attackers to crash the Serv-U service...
Key Takeaways
- A critical vulnerability in SolarWinds Serv-U, tracked as CVE-2026-28318, is being actively exploited in the wild.
- The flaw allows unauthenticated attackers to crash the Serv-U service remotely by sending specially crafted HTTP requests.
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.
- A patch is available in Serv-U version 15.5.4 Hotfix 1, and immediate application is strongly recommended.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a significant alert regarding a critical vulnerability within SolarWinds Serv-U software, confirming active exploitation by malicious actors. The flaw, now listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, poses an immediate risk to organizations utilizing the affected file transfer solution.
Table Of Content
Designated as CVE-2026-28318, this security hole enables unauthenticated attackers to trigger a denial-of-service condition, effectively crashing the Serv-U application. This is achieved by sending specific HTTP requests that exploit an uncontrolled resource consumption mechanism within the software.
The vulnerability falls under the CWE-400 category, characterized by an application’s failure to adequately manage the resources it allocates when processing incoming data. In this particular scenario, an attacker can dispatch a malicious POST request that includes the Content-Encoding: deflate HTTP header. This action forces the Serv-U service to consume excessive system resources, leading to an immediate crash without requiring any prior authentication.
The severity of this exploit is heightened by its nature: it requires no authentication and can be executed remotely across a network. This makes CVE-2026-28318 an attractive initial access vector for threat actors targeting organizations that have exposed their Serv-U deployments to the public internet.
CISA officially added CVE-2026-28318 to its KEV catalog on June 5, 2026. Federal Civilian Executive Branch (FCEB) agencies are mandated to remediate this vulnerability by June 19, 2026, in accordance with Binding Operational Directive (BOD) 22-01. While there is no current confirmation linking this specific vulnerability to ransomware campaigns, CISA urges all organizations, irrespective of their federal status, to prioritize remediation due to the confirmed active exploitation.
Affected Products and Patch Availability
SolarWinds has released a crucial hotfix to address CVE-2026-28318. The patch is available in Serv-U version 15.5.4 Hotfix 1. Any organization running earlier versions of Serv-U is vulnerable and must apply this update without delay.
Further details and the official security advisory have been published by SolarWinds via its Trust Center. Comprehensive technical information is also accessible through the NVD entry for CVE-2026-28318.
What You Should Do
- Immediately apply the SolarWinds Serv-U 15.5.4 Hotfix 1 patch to all vulnerable instances.
- Where feasible, restrict public exposure of the Serv-U service by placing it behind a firewall or a Virtual Private Network (VPN).
- Actively monitor network logs for any anomalous POST requests that contain the
Content-Encoding: deflateheader. - If immediate patching is not possible, consider temporarily disabling or decommissioning Serv-U instances until the fix can be applied.
- Organizations with cloud-hosted Serv-U deployments should adhere to the guidance provided in BOD 22-01.
- Consult the official SolarWinds advisory and the NIST NVD entry for the most up-to-date technical details and patching instructions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.