CVE-2026-28318 is a high-severity DoS vulnerability in SolarWinds Serv-U actively exploited in the wild. Patch to 15.5.4 Hotfix 1 immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| serv-u | * | 15.5.4 | vulnerable |
| serv-u | 15.5.4 | 15.5.4 | vulnerable |
Install SolarWinds Serv-U 15.5.4 Hotfix 1 immediately. This update addresses the improper handling of 'Content-Encoding: deflate' headers that leads to service instability.
Identify all instances of SolarWinds Serv-U running versions 15.5.4 or earlier. Ensure these systems are upgraded to the latest secure release to eliminate the DoS vector.
Place Serv-U instances behind a Web Application Firewall (WAF) and configure rules to inspect POST requests. If possible, restrict access to the management interface to trusted IP ranges only.
Enable detailed logging for the Serv-U service and monitor for frequent, unexplained service crashes. Watch for HTTP POST requests containing the 'Content-Encoding: deflate' header from untrusted sources.
Detecting exploitation of CVE-2026-28318 involves monitoring network traffic for HTTP POST requests that utilize the 'Content-Encoding: deflate' header, particularly those originating from external or suspicious IP addresses. Administrators should also review system event logs for frequent crashes of the Serv-U.exe process. Implementing IDS/IPS signatures that flag malformed deflate-encoded payloads can provide early warning of an ongoing attack against the file transfer service.
Experience superior visibility and a simpler approach to cyber risk management