HIGH 7.5CISA KEV — Actively Exploited

CVE-2026-28318: SolarWinds Serv-U Unauthenticated Denial-of-Service Vulnerability

SolarWinds Serv-U contains a denial-of-service vulnerability that allows unauthenticated attackers to crash the service by sending specially crafted POST requests using Content-Encoding: deflate compression. An attacker on the network can trigger this flaw without credentials, causing service unavailability. The vulnerability does not enable unauthorized data access or modification, but the ability to reliably crash the service without authentication makes it a significant operational risk.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
CWE-400
Affected products
2 configuration(s)
Published / Modified
2026-06-04 / 2026-06-17
KEV due date
2026-06-19 (added 2026-06-05)

NVD description (verbatim)

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

3 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-28318 is a CWE-400 (Uncontrolled Resource Consumption) flaw in SolarWinds Serv-U triggered via malformed POST requests that specify Content-Encoding: deflate. The vulnerability bypasses authentication requirements and results in denial of service to the Serv-U process. The CVSS 3.1 score of 7.5 (HIGH) reflects network accessibility, low attack complexity, no privilege requirement, and high availability impact with no confidentiality or integrity compromise.

Business impact

Service disruption to file transfer and remote access operations represents the primary risk. Organizations relying on Serv-U for managed file transfer or secure shell access face availability losses during an active denial-of-service condition. Recovery requires manual service restart. Unlike exploits that exfiltrate data, this threat model targets operational continuity; however, repeated or sustained attacks could degrade customer-facing SLA compliance and require incident response overhead.

Affected systems

SolarWinds Serv-U installations are affected. Confirm your specific version against the vendor's patched releases via the SolarWinds Trust Center advisory. Both client and server deployments of Serv-U may be vulnerable; verification of your deployed version is essential before assuming exposure or immunity.

Exploitability

The vulnerability is highly exploitable in practice. Attack requires only network access and no authentication, making it trivial to weaponize from any vantage point that can reach the Serv-U service port. The low attack complexity and absence of user interaction mean automated scanning and exploitation are feasible. The vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on 2026-06-05, indicating active exploitation in the wild and the likely availability of functional proof-of-concept code.

Remediation

Apply the SolarWinds security update for Serv-U as advised in the vendor advisory. Organizations unable to patch immediately should implement network segmentation to restrict access to Serv-U administrative and service ports, limit POST requests from untrusted origins, or temporarily disable the service if operationally feasible. Review the SolarWinds Trust Center for detailed mitigation steps tailored to your deployment model.

Patch guidance

Obtain the patched Serv-U build from SolarWinds' official release channels and security advisory. Verify patch applicability to your current version before deployment. Test patches in a non-production environment to confirm compatibility with your file transfer workflows and integrations. The CISA KEV due date of 2026-06-19 establishes a deadline for federal agencies and critical infrastructure; other organizations should prioritize patching within one to two weeks of publication.

Detection guidance

Monitor Serv-U logs and service health dashboards for unexpected restarts or crashes correlating with POST request spikes. Implement network-based detection for malformed Content-Encoding: deflate headers directed at Serv-U ports. Alert on repeated failed or crash-triggering requests from suspicious sources. Correlate process termination events with incoming network traffic patterns to identify potential attack attempts. Review firewall and reverse-proxy logs for anomalous POST request payloads.

Why prioritize this

This vulnerability warrants immediate attention due to its HIGH CVSS score, presence in the CISA KEV catalog indicating active exploitation, unauthenticated attack surface, and direct impact on service availability. The combination of trivial exploitability and operational consequences—especially for organizations using Serv-U as a critical file transfer backbone—demands rapid patch deployment or compensating controls within the CISA due date window.

Risk score, explained

The CVSS 3.1 score of 7.5 reflects the threat model: network-accessible, no authentication required, low attack complexity, and high availability impact. The absence of confidentiality or integrity compromise prevents a critical rating, but the uncontrolled resource consumption nature of the flaw and its proven real-world exploitation justify the HIGH severity classification. Organizations with Serv-U exposed to the internet or untrusted networks face acute risk.

Frequently asked questions

Can this vulnerability be exploited to steal data or modify files?

No. CVE-2026-28318 causes denial of service only; it does not enable unauthorized data access or modification. The attack crashes the Serv-U process, disrupting availability, but does not compromise confidentiality or integrity of stored or transferred data.

Do I need to be a customer or have credentials to exploit this?

No. The vulnerability requires only network access to the Serv-U service port and no authentication. Any attacker able to send crafted POST requests to the service can trigger the crash, making it accessible from the internet if Serv-U is exposed without firewall restrictions.

How urgent is patching if Serv-U is behind a firewall with restricted access?

Patching remains urgent but slightly less critical if Serv-U is restricted to trusted networks or VPN access only. However, network segmentation can fail or be misconfigured; patching eliminates the vulnerability entirely and is the preferred long-term remediation regardless of network posture.

What should I do if I cannot patch immediately?

Immediately apply network mitigations: restrict POST requests to Serv-U from authorized sources only, implement rate-limiting on service endpoints, disable the service if operationally feasible, and monitor logs for crash events. Consult the SolarWinds Trust Center for environment-specific mitigation guidance, and establish a patch deployment timeline within the CISA due date.

This analysis is provided for educational and defensive security purposes. Organizations should verify all patch versions and vendor advisories directly with SolarWinds official channels before deploying updates. The presence of a vulnerability in CISA's KEV catalog indicates observed exploitation in the wild; however, this does not constitute a guarantee of widespread or imminent attacks in your specific environment. Network and access controls should be layered alongside patching. Consult your security team and SolarWinds support for guidance specific to your deployment and risk tolerance. Source: NVD (public-domain), retrieved 2026-07-14. Analysis generated by SEC.co (claude-haiku-4-5).

Preview — this page is review (quality 1). high-value: hold for review.