Vulnerabilities
CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
Cyber RTJune 6, 20263 min read

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity flaw in SolarWinds Serv-U software to its Known Exploited Vulnerabilities catalog due to active exploitation. The denial-of-service vulnerability (CVE-2026-28318) crashes the service via crafted POST requests. SolarWinds addressed it in version 15.5.4 HF1, advising access limitations and blocking specific requests. CISA mandates federal agencies to fix it by June 19, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog to include a high-severity security flaw affecting SolarWinds Serv-U, a multi-protocol file server software. This addition is based on evidence indicating active exploitation of the vulnerability. The flaw, identified as CVE-2026-28318, has been assigned a Common Vulnerability Scoring System (CVSS) score of 7.5, highlighting its significant impact.
The vulnerability is characterized as a denial-of-service (DoS) bug, which can lead to the service crashing under specific conditions. CISA has described this issue as an uncontrolled resource consumption vulnerability, which results in a DoS condition. This type of vulnerability can severely disrupt the functionality of the affected software, making it a critical concern for organizations using SolarWinds Serv-U.
According to an advisory released by SolarWinds, the Serv-U software is vulnerable to specially crafted POST requests that can crash the service without requiring authentication. These requests exploit the Content-Encoding: deflate feature, which the software does not need, to trigger the vulnerability. This makes the flaw particularly dangerous as it can be exploited without any authentication barriers.
SolarWinds has addressed this issue in the latest version of its software, Serv-U version 15.5.4 HF1. As part of the mitigation strategy, it is recommended that users limit access to known addresses and block any requests containing "content-encoding." These measures are intended to prevent unauthorized exploitation of the vulnerability while ensuring the continued security of the system.
Currently, there is limited information available about the real-world exploitation of this vulnerability. Details regarding the methods of exploitation or the identity of the attackers remain unclear. Additionally, it is not known how many internet-exposed Serv-U instances might be compromised, if any, which adds to the uncertainty surrounding the threat.
In response to the vulnerability, CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies address the flaw by June 19, 2026. This directive underscores the importance of promptly mitigating the vulnerability to protect critical infrastructure. Historically, SolarWinds Serv-U has been targeted by various threat actors, including those linked to the Cl0p ransomware gang, highlighting the need for vigilance.
For those interested in staying informed about cybersecurity developments, the article encourages following CISA on platforms like Google News, Twitter, and LinkedIn. These channels provide access to exclusive content and updates on cybersecurity threats and mitigation strategies, helping organizations and individuals stay ahead of potential risks.


