Vulnerability record · CVE-2026-28318 · published 4 June 2026
CVE-2026-28318: SolarWinds Serv-U unauthenticated POST request denial of service
Solarwinds · Serv U
SolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authentication. The flaw is an uncontrolled resource consumption issue (CWE-400) that lets an unauthenticated remote party take the service down. SolarWinds has published a hotfix and mitigation guidance for environments that cannot update immediately.
Description
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote denial of service with CISA KEV listing and high EPSS, though impact is limited to availability.
What it is
SolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authentication. The flaw is an uncontrolled resource consumption issue (CWE-400) that lets an unauthenticated remote party take the service down. SolarWinds has published a hotfix and mitigation guidance for environments that cannot update immediately.
Impact
An attacker can crash the Serv-U service, causing a denial of service for file transfer operations. There is no confidentiality or integrity impact per the CVSS vector; the effect is availability loss only.
Attack surface
The flaw is reachable over the network via HTTP POST requests to the Serv-U service, with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any host that can reach the Serv-U listener can attempt it.
Exploitation
CVE-2026-28318 was added to CISA KEV on 2026-06-05 with a 2026-06-19 remediation due date, indicating known exploitation in the wild. EPSS is 0.40012 (98.6th percentile), and no ransomware campaign use is documented.
What to do
- Apply the SolarWinds Serv-U 15.5.4 Hotfix 1 update or later as the primary fix.
- If patching is not possible, apply the mitigation steps in the SolarWinds Trust Center advisory for CVE-2026-28318.
- Restrict network access to the Serv-U service to trusted hosts and networks only.
- Follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Monitor for and block POST requests carrying Content-Encoding: deflate where they are not expected.
Detection
- Alert on Serv-U service crashes or unexpected restarts and correlate with inbound POST traffic.
- Search web or proxy logs for POST requests to Serv-U endpoints with a Content-Encoding: deflate header.
- Baseline normal Serv-U request volume and flag spikes or repeated malformed POST attempts from single sources.
- Review Serv-U and host logs for availability gaps matching the KEV remediation window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities catalog on 5 June 2026 as "SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 June 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-28318 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-28318), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.