Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-28318

Published 2026-06-04
Updated 2 months ago
Vendor/s
SolarWinds
Product/s
Serv-U
Version/s
* > 15.5.4
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
7.5
/ 10
High
Severity Details
Base score
7.5 High
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Description

CVE-2026-28318 is a high-severity DoS vulnerability in SolarWinds Serv-U actively exploited in the wild. Patch to 15.5.4 Hotfix 1 immediately.

CPE

SolarWinds logo
SolarWinds
Product Version Start Version End (excl.) Status
serv-u * 15.5.4 vulnerable
serv-u 15.5.4 15.5.4 vulnerable

Related weakness (CWE)

CWE-400

Remediation plan

1

Apply official patches

Install SolarWinds Serv-U 15.5.4 Hotfix 1 immediately. This update addresses the improper handling of 'Content-Encoding: deflate' headers that leads to service instability.

2

Update affected systems

Identify all instances of SolarWinds Serv-U running versions 15.5.4 or earlier. Ensure these systems are upgraded to the latest secure release to eliminate the DoS vector.

3

Restrict access

Place Serv-U instances behind a Web Application Firewall (WAF) and configure rules to inspect POST requests. If possible, restrict access to the management interface to trusted IP ranges only.

4

Monitor for exploitation

Enable detailed logging for the Serv-U service and monitor for frequent, unexplained service crashes. Watch for HTTP POST requests containing the 'Content-Encoding: deflate' header from untrusted sources.

Detection Guidance

Detecting exploitation of CVE-2026-28318 involves monitoring network traffic for HTTP POST requests that utilize the 'Content-Encoding: deflate' header, particularly those originating from external or suspicious IP addresses. Administrators should also review system event logs for frequent crashes of the Serv-U.exe process. Implementing IDS/IPS signatures that flag malformed deflate-encoded payloads can provide early warning of an ongoing attack against the file transfer service.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management