Skip to content
Actively exploitedCVSS 7.5 · HIGH

CVE-2026-28318

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

View on NVD

Analysis

SolarWinds Serv-U es vulnerable a ataques de denegación de servicio que permiten a un atacante remoto colapsar el servicio sin necesidad de autenticación mediante peticiones POST maliciosas. Esta vulnerabilidad está siendo explotada activamente en entornos reales, por lo que es crítico actualizar la herramienta para evitar interrupciones en procesos de transferencia de archivos. Los atacantes aprovechan el manejo de encabezados específicos para agotar los recursos del servidor de manera inmediata.

Relevant roles

BackendCyberSecurityWindowsLinuxCloud

Severity

Score: 7.5(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: NONE
I: NONE
A: HIGH
Weakness (CWE): CWE-400

CISA KEV

Added to KEV: 2026-06-05
Federal patch deadline: 2026-06-19
Known ransomware use: Unknown
Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS

Probability of exploitation (next 30 days): 0.0006 (0.1%)
Percentile: 19.7%
EPSS: 2026-06-05

Affects

solarwinds:serv-u

Technical description

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

Published: 6/4/2026, 3:16:50 PM
Last modified: 6/5/2026, 7:32:38 PM

References

HomeEventsBlogResourcesTeam