CISA warned that attackers are actively exploiting SolarWinds Serv-U vulnerability CVE-2026-28318, a recently patched high-severity denial-of-service flaw in the company's managed file transfer and FTP server software for Windows and Linux. The bug can be triggered through low-complexity, unauthenticated POST requests—reported to include the Content-Encoding: deflate header—causing the Serv-U service to crash through uncontrolled resource consumption. CISA has added the issue to its Known Exploited Vulnerabilities catalog and directed Federal Civilian Executive Branch agencies to remediate by June 19 under Binding Operational Directive 22-01.
SolarWinds said the flaw is fixed in Serv-U 15.5.4 Hotfix 1, while CISA urged private-sector organizations to apply mitigations immediately or discontinue use if mitigations are unavailable. Reporting also noted that thousands of Serv-U servers remain exposed online, expanding the potential attack surface. The warning comes amid a broader pattern of SolarWinds Serv-U exploitation, with earlier campaigns tied to the Clop ransomware gang, DEV-0322 Chinese threat actors, and abuse of prior Serv-U vulnerabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to remediate the flaw under Binding Operational Directive 22-01. The deadline given to federal agencies was June 19, and CISA also urged private-sector organizations to apply mitigations quickly.
CISA warned that attackers are actively exploiting CVE-2026-28318 in SolarWinds Serv-U to crash vulnerable servers. The agency said the denial-of-service issue can be exploited with low-complexity, unauthenticated POST requests.
SolarWinds released Serv-U 15.5.4 Hotfix 1 to fix CVE-2026-28318, a high-severity denial-of-service flaw caused by uncontrolled resource consumption. The bug affects Serv-U managed file transfer and FTP server software on Windows and Linux and can be triggered with crafted unauthenticated POST requests.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceccb.belgium.be
Open sourcethecyberthrone.in
Open sourcearetiq.ai
Open sourcesecurityonline.info
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcedocumentation.solarwinds.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.