← Vulnerability feed

Vulnerability record · CVE-2026-28318 · published 4 June 2026

CVE-2026-28318: SolarWinds Serv-U unauthenticated POST request denial of service

Solarwinds · Serv U

SolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authentication. The flaw is an uncontrolled resource consumption issue (CWE-400) that lets an unauthenticated remote party take the service down. SolarWinds has published a hotfix and mitigation guidance for environments that cannot update immediately.

7.5 CVSS 3.1 High CISA KEV since 5 Jun 2026 EPSS 1.9% · top 20.7% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score
1.9%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
22 Jul 2026Last modified by NVD

Description

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityUnauthenticated remote denial of service with CISA KEV listing and high EPSS, though impact is limited to availability.

What it is

SolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authentication. The flaw is an uncontrolled resource consumption issue (CWE-400) that lets an unauthenticated remote party take the service down. SolarWinds has published a hotfix and mitigation guidance for environments that cannot update immediately.

Impact

An attacker can crash the Serv-U service, causing a denial of service for file transfer operations. There is no confidentiality or integrity impact per the CVSS vector; the effect is availability loss only.

Attack surface

The flaw is reachable over the network via HTTP POST requests to the Serv-U service, with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any host that can reach the Serv-U listener can attempt it.

Exploitation

CVE-2026-28318 was added to CISA KEV on 2026-06-05 with a 2026-06-19 remediation due date, indicating known exploitation in the wild. EPSS is 0.40012 (98.6th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the SolarWinds Serv-U 15.5.4 Hotfix 1 update or later as the primary fix.
  • If patching is not possible, apply the mitigation steps in the SolarWinds Trust Center advisory for CVE-2026-28318.
  • Restrict network access to the Serv-U service to trusted hosts and networks only.
  • Follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
  • Monitor for and block POST requests carrying Content-Encoding: deflate where they are not expected.

Detection

  • Alert on Serv-U service crashes or unexpected restarts and correlate with inbound POST traffic.
  • Search web or proxy logs for POST requests to Serv-U endpoints with a Content-Encoding: deflate header.
  • Baseline normal Serv-U request volume and flag spikes or repeated malformed POST attempts from single sources.
  • Review Serv-U and host logs for availability gaps matching the KEV remediation window.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities catalog on 5 June 2026 as "SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 June 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-28318 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-35211SolarWinds Serv-U out-of-bounds write enables remote code executionSolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 contain an out-of-bounds write (CWE-787) that Microsoft d…KEVEPSS 91%analysed7.5CVE-2024-28995SolarWinds Serv-U path traversal allows arbitrary file readSolarWinds Serv-U contains a path traversal flaw (CWE-22) that lets an unauthenticated remote attacker read sensitive files from the host. The vulner…KEVEPSS 100%analysed5.3CVE-2021-35247SolarWinds Serv-U web login LDAP input validation flawThe Serv-U web login screen passed characters to LDAP authentication without sufficient sanitization. SolarWinds updated the input mechanism to add v…KEVEPSS 3.5%analysed9.8CVE-2020-35481Solarwinds serv-u vulnerabilitySolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.EPSS 1.3%9.1CVE-2026-28317Solarwinds serv-u insecure direct object reference vulnerabilitySolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires …EPSS 0.50%9.1CVE-2026-28321Solarwinds serv-u improper access control vulnerabilitySolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to esca…EPSS 0.58%9.1CVE-2026-28312Solarwinds serv-u improper authorization vulnerabilitySolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code exe…EPSS 0.58%9.1CVE-2026-28313Solarwinds serv-u insecure direct object reference vulnerabilitySolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary accoun…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2026-28318), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.