U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-28318 | Unauthenticated DoS in SolarWinds Serv-U via crafted Content-Encoding: deflate POSTs SolarWinds Serv-U, an FTP and managed-file-transfer server, contains an uncontrolled resource consumption flaw (CWE-400) that allows an unauthenticated remote attacker to exhaust the service's resources. It is triggered by sending specially crafted POST requests with the Content-Encoding: deflate header, which crashes the Serv-U service. An attacker gains denial of service — file transfer operations stop until the service is restarted — and the available data indicates no remote code execution or data exposure. Any organization running Serv-U, typically enterprises using it as an internal or internet-facing file transfer endpoint, is affected; the available advisories do not specify affected version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-05, signaling exploitation in the wild, and EPSS estimates a 40% probability of exploitation within 30 days (99th percentile), though CVSS scoring is pending and no public proof-of-concept is known. Do: Inventory all Serv-U deployments and apply SolarWinds' mitigation per vendor instructions, or discontinue use of the product if mitigations are unavailable, as required by the KEV listing (federal agencies must follow BOD 22-01 timelines). As an interim mitigation, block or normalize POST requests carrying the Content-Encoding: deflate header at a WAF or reverse proxy and restrict Serv-U's internet exposure. Monitor the Serv-U service for crashes, since successful exploitation takes it down until it is restarted. | 7.5 | 40% | KEV |
| moderate≈tens of thousands of installations; only a few thousand Serv-U servers exposed to the internet |
Full article274 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SolarWinds Serv-U flaw, tracked as CVE-2026-28318 (CVSS ver 3.1 score of 7.5), to its Known Exploited Vulnerabilities (KEV) catalog. SolarWinds Serv-U is a managed file transfer (MFT) and secure file server platform developed by SolarWinds
The CVE-2026-28318 flaw is an unauthenticated denial-of-service (DoS) vulnerability affecting SolarWinds Serv-U. The issue allows a remote attacker to send a specially crafted HTTP POST request using the Content-Encoding: deflate header, causing the Serv-U service to crash without requiring valid credentials.
Successful exploitation can disrupt file transfer operations and make the service unavailable to legitimate users. SolarWinds has released security updates to address the vulnerability and recommends applying them as soon as possible. For organizations unable to deploy the patch immediately, mitigation measures are available through the SolarWinds Trust Center.
“SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate.” reads the advisory.
The flaw affects SolarWinds Serv-U 15.5.4 and earlier; Serv-U 15.5.4 HF1 addressed the issue.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerability by June 19, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/193245/security/u-s-cisa-adds-solarwinds-serv-u-flaw-to-its-known-exploited-vulnerabilities-catalog.html