CISA Warns of Actively Exploited SolarWinds Serv-U Vulnerability
Want more insights like this?
CISA added a high-severity SolarWinds Serv-U flaw, CVE-2026-28318 (CVSS 7.5), to its Known Exploited Vulnerabilities catalog on June 5, 2026 — the same day SolarWinds shipped the fix — with a remediation deadline of June 19 for federal agencies.
The vulnerability lets unauthenticated attackers crash Serv-U file transfer software remotely by sending a malicious POST request with a Content-Encoding: deflate header — no credentials required. That zero-privilege, network-accessible attack path makes it especially dangerous for organizations with Serv-U exposed to the internet. SolarWinds' own advisory made no mention of exploitation, and it's still unclear whether the flaw was used as a zero-day.
The fix is Serv-U 15.5.4 Hotfix 1, and the affected releases — 15.4.2, 15.5 and 15.5.1 — have already reached end of life, so some organisations will need an upgrade rather than a patch. Restrict Serv-U exposure behind a firewall or VPN, and monitor logs for suspicious POST requests.
Source: Cybersecurity News