CISA Flags Active Exploitation of SolarWinds Serv-U DoS Flaw
CISA has added a high-severity SolarWinds Serv-U denial-of-service flaw to its KEV catalog, citing active exploitation. The bug, CVE-2026-28318, lets unauthenticated attackers crash servers via crafted POST requests. Federal agencies must patch by June 19.
The U.S. Cybersecurity and Infrastructure Security Agency has added a high-severity denial-of-service vulnerability in SolarWinds Serv-U to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The flaw, tracked as CVE-2026-28318 and carrying a CVSS score of 7.5, allows unauthenticated attackers to crash the multi-protocol file server software.
SolarWinds released a fix in Serv-U version 15.5.4 HF1 after discovering that specially crafted POST requests using Content-Encoding: deflate can exhaust system resources without authentication. The company described the issue as an uncontrolled resource consumption vulnerability that results in a complete service outage.
Exploitation Details and Mitigations
CISA has ordered Federal Civilian Executive Branch agencies to remediate the vulnerability by June 19, 2026. The agency has not disclosed specific details about real-world attacks or the threat actors behind them, nor has it confirmed how many internet-exposed Serv-U instances have been compromised.
SolarWinds advised administrators to take the following steps:
- Apply the 15.5.4 HF1 patch immediately.
- Limit access to Serv-U interfaces to known, trusted IP addresses.
- Block any HTTP request containing the "Content-Encoding" header, as the vulnerable service does not require this functionality.
Historical Context and Broader Risks
This is not the first time SolarWinds Serv-U has been a target. In previous campaigns, the Cl0p ransomware gang exploited separate flaws in the same product to breach corporate networks and deploy data-stealing malware. The reappearance of Serv-U vulnerabilities in active exploits underscores the persistent risk posed by internet-facing file transfer software.
The uncontrolled resource consumption bug affects all versions of Serv-U prior to 15.5.4 HF1. Because the attack requires no authentication and no user interaction, any publicly accessible Serv-U instance is a potential target. Organizations that have not yet patched are at immediate risk of service disruption, and in environments where Serv-U is a critical file transfer gateway, a sustained denial-of-service condition can halt business operations.
Security researchers have not published proof-of-concept code for CVE-2026-28318, but the technical details in SolarWinds' advisory are specific enough that skilled attackers can replicate the crash. The inclusion in CISA's KEV catalog means that federal agencies must treat the flaw as an active threat, and private sector organizations are strongly urged to follow the same timeline.
What comes next: CISA will monitor compliance among federal agencies and may issue supplemental guidance if exploitation activity escalates. SolarWinds customers still running older Serv-U builds should treat this as an emergency patch event. According to BleepingComputer, the agency warned that hackers are now actively exploiting the flaw to crash servers, reinforcing the urgency of immediate patching.
Fact check
-
CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities catalog citing active exploitation.
verified · source
-
The vulnerability is an uncontrolled resource consumption flaw with a CVSS score of 7.5.
verified · source
-
SolarWinds released a fix in Serv-U version 15.5.4 HF1.
verified · source
-
CISA ordered FCEB agencies to remediate the flaw by June 19, 2026.
verified · source
-
The Cl0p ransomware gang previously exploited Serv-U flaws in past campaigns.
reported · source
Source reporting (2)
Related Articles
Snowflake hacker pleads guilty to stealing data from 165 organizations, faces 32 years in prison
Aug 5, 2026
AI Agents From OpenAI and Anthropic Breach Real Websites During Security Tests
Aug 5, 2026
AI Agent Security Startups Zenity and Horizon3.ai Raise $375M Combined as SentinelOne Expands Autonomous SOC
Aug 3, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.