CVE-2026-28318: SolarWinds Serv-U Unauthenticated Denial-of-Service Vulnerability
SolarWinds Serv-U contains a denial-of-service vulnerability that allows unauthenticated attackers to crash the service by sending specially crafted POST requests using Content-Encoding: deflate compression. An attacker on the network can trigger this flaw without credentials, causing service unavailability. The vulnerability does not enable unauthorized data access or modification, but the ability to reliably crash the service without authentication makes it a significant operational risk.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-400
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-04 / 2026-06-17
- KEV due date
- 2026-06-19 (added 2026-06-05)
NVD description (verbatim)
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-28318 is a CWE-400 (Uncontrolled Resource Consumption) flaw in SolarWinds Serv-U triggered via malformed POST requests that specify Content-Encoding: deflate. The vulnerability bypasses authentication requirements and results in denial of service to the Serv-U process. The CVSS 3.1 score of 7.5 (HIGH) reflects network accessibility, low attack complexity, no privilege requirement, and high availability impact with no confidentiality or integrity compromise.
Business impact
Service disruption to file transfer and remote access operations represents the primary risk. Organizations relying on Serv-U for managed file transfer or secure shell access face availability losses during an active denial-of-service condition. Recovery requires manual service restart. Unlike exploits that exfiltrate data, this threat model targets operational continuity; however, repeated or sustained attacks could degrade customer-facing SLA compliance and require incident response overhead.
Affected systems
SolarWinds Serv-U installations are affected. Confirm your specific version against the vendor's patched releases via the SolarWinds Trust Center advisory. Both client and server deployments of Serv-U may be vulnerable; verification of your deployed version is essential before assuming exposure or immunity.
Exploitability
The vulnerability is highly exploitable in practice. Attack requires only network access and no authentication, making it trivial to weaponize from any vantage point that can reach the Serv-U service port. The low attack complexity and absence of user interaction mean automated scanning and exploitation are feasible. The vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on 2026-06-05, indicating active exploitation in the wild and the likely availability of functional proof-of-concept code.
Remediation
Apply the SolarWinds security update for Serv-U as advised in the vendor advisory. Organizations unable to patch immediately should implement network segmentation to restrict access to Serv-U administrative and service ports, limit POST requests from untrusted origins, or temporarily disable the service if operationally feasible. Review the SolarWinds Trust Center for detailed mitigation steps tailored to your deployment model.
Patch guidance
Obtain the patched Serv-U build from SolarWinds' official release channels and security advisory. Verify patch applicability to your current version before deployment. Test patches in a non-production environment to confirm compatibility with your file transfer workflows and integrations. The CISA KEV due date of 2026-06-19 establishes a deadline for federal agencies and critical infrastructure; other organizations should prioritize patching within one to two weeks of publication.
Detection guidance
Monitor Serv-U logs and service health dashboards for unexpected restarts or crashes correlating with POST request spikes. Implement network-based detection for malformed Content-Encoding: deflate headers directed at Serv-U ports. Alert on repeated failed or crash-triggering requests from suspicious sources. Correlate process termination events with incoming network traffic patterns to identify potential attack attempts. Review firewall and reverse-proxy logs for anomalous POST request payloads.
Why prioritize this
This vulnerability warrants immediate attention due to its HIGH CVSS score, presence in the CISA KEV catalog indicating active exploitation, unauthenticated attack surface, and direct impact on service availability. The combination of trivial exploitability and operational consequences—especially for organizations using Serv-U as a critical file transfer backbone—demands rapid patch deployment or compensating controls within the CISA due date window.
Risk score, explained
The CVSS 3.1 score of 7.5 reflects the threat model: network-accessible, no authentication required, low attack complexity, and high availability impact. The absence of confidentiality or integrity compromise prevents a critical rating, but the uncontrolled resource consumption nature of the flaw and its proven real-world exploitation justify the HIGH severity classification. Organizations with Serv-U exposed to the internet or untrusted networks face acute risk.
Frequently asked questions
Can this vulnerability be exploited to steal data or modify files?
No. CVE-2026-28318 causes denial of service only; it does not enable unauthorized data access or modification. The attack crashes the Serv-U process, disrupting availability, but does not compromise confidentiality or integrity of stored or transferred data.
Do I need to be a customer or have credentials to exploit this?
No. The vulnerability requires only network access to the Serv-U service port and no authentication. Any attacker able to send crafted POST requests to the service can trigger the crash, making it accessible from the internet if Serv-U is exposed without firewall restrictions.
How urgent is patching if Serv-U is behind a firewall with restricted access?
Patching remains urgent but slightly less critical if Serv-U is restricted to trusted networks or VPN access only. However, network segmentation can fail or be misconfigured; patching eliminates the vulnerability entirely and is the preferred long-term remediation regardless of network posture.
What should I do if I cannot patch immediately?
Immediately apply network mitigations: restrict POST requests to Serv-U from authorized sources only, implement rate-limiting on service endpoints, disable the service if operationally feasible, and monitor logs for crash events. Consult the SolarWinds Trust Center for environment-specific mitigation guidance, and establish a patch deployment timeline within the CISA due date.
This analysis is provided for educational and defensive security purposes. Organizations should verify all patch versions and vendor advisories directly with SolarWinds official channels before deploying updates. The presence of a vulnerability in CISA's KEV catalog indicates observed exploitation in the wild; however, this does not constitute a guarantee of widespread or imminent attacks in your specific environment. Network and access controls should be layered alongside patching. Consult your security team and SolarWinds support for guidance specific to your deployment and risk tolerance. Source: NVD (public-domain), retrieved 2026-07-14. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2024-14036HIGHDräger Core Denial of Service via Malformed SDC Messages
- CVE-2026-10069HIGHShibby Tomato miniupnpd Resource Exhaustion Vulnerability
- CVE-2026-35266HIGHOracle REST Data Services Authentication & Data Integrity Vulnerability
- CVE-2026-35277HIGHOracle REST Data Services Authorization Bypass
- CVE-2026-37234HIGHFlexRIC E42 Resource Leak via Multiple xapp_id Binding
- CVE-2026-40983HIGHMicrometer gRPC Denial-of-Service Vulnerability
- CVE-2026-40984HIGHMicrometer Denial-of-Service Vulnerability – HTTP Request Handling Flaw
- CVE-2026-41842HIGHSpring Framework DoS Vulnerability in Static Resource Resolution
Preview — this page is review (quality 1). high-value: hold for review.