<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

CISA Warns of Actively Exploited SolarWinds Serv-U Vulnerability

High-severity Serv-U flaw CVE-2026-28318 added to CISA's catalog. Patch urgently to prevent remote crashes via malicious POST requests.
Content Team

CISA added a high-severity SolarWinds Serv-U flaw, CVE-2026-28318 (CVSS 7.5), to its Known Exploited Vulnerabilities catalog on June 5, 2026 — the same day SolarWinds shipped the fix — with a remediation deadline of June 19 for federal agencies.

The vulnerability lets unauthenticated attackers crash Serv-U file transfer software remotely by sending a malicious POST request with a Content-Encoding: deflate header — no credentials required. That zero-privilege, network-accessible attack path makes it especially dangerous for organizations with Serv-U exposed to the internet. SolarWinds' own advisory made no mention of exploitation, and it's still unclear whether the flaw was used as a zero-day.

The fix is Serv-U 15.5.4 Hotfix 1, and the affected releases — 15.4.2, 15.5 and 15.5.1 — have already reached end of life, so some organisations will need an upgrade rather than a patch. Restrict Serv-U exposure behind a firewall or VPN, and monitor logs for suspicious POST requests.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo