CVE-2026-28318
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
Description
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
Description as published by the source, in English.
Key facts
- Published
- 2026-06-04
- Last modified
- 2026-07-22
- Assigned by
- psirt@solarwinds.com
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Scored by
- psirt@solarwinds.com
- Probability of exploitation
-
8.4 %
higher than 94 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-06-05, with a remediation deadline of 2026-06-19 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Solarwinds | Serv-u | < 15.5.4 | Affected |
| Solarwinds | Serv-u | 15.5.4 | Affected |
Weakness type
-
CWE-400: Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Attack techniques
Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.
- T1499: Endpoint Denial of Service
References
- https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_…
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28318
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-28318
Related at Berigo
Articles
-
CISA adds eight exploited vulnerabilities to its KEV catalogue
Same product
2026-03-09
Over five days CISA added eight flaws to its Known Exploited Vulnerabilities catalogue, spanning Hikvision, Rockwell, Apple, SolarWinds and Ivanti.
-
CISA adds four exploited vulnerabilities to the KEV catalog
Same product
2026-02-03
The flaws affect Sangoma FreePBX, GitLab and SolarWinds Web Help Desk, spanning from 2019 to one published a week ago.
-
Critical SolarWinds Web Help Desk flaw allows code execution without login
Same product
2026-01-28
CVE-2025-40551 lets an unauthenticated attacker run code on the server through unsafe deserialisation, rated CVSS 9.8.
-
CodeBreach: a CodeBuild misconfiguration exposed AWS repositories
Same product
2026-01-15
Wiz researchers found a supply chain flaw granting administrative access to the AWS SDK for JavaScript repository. AWS has closed the attack vector.
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.