SolarWinds Serv-U versions 15.5.4.108 and earlier are affected by CVE-2026-28318, an unauthenticated denial-of-service flaw that can crash the service through the default-enabled web interface. Bishop Fox reported that a single POST request carrying a Content-Encoding: deflate header and any body can trigger heap corruption caused by an invalid free() in the product’s in-memory decompressor, aborting the Serv-U process. Although the bug initially raised concern about possible memory-corruption exploitation, testing found the practical impact to be service availability loss rather than remote code execution.
SolarWinds addressed the issue in Serv-U 15.5.4 HF1 by rejecting requests that include a body and a non-empty Content-Encoding header with HTTP 415 before the body is processed; patched builds are identified as 15.5.4.125 or later. Bishop Fox also published a production-safe detection tool on GitHub that avoids sending the crashing input and instead checks for the 415 response using a benign request, while warning that reverse proxies or load balancers may affect results. Organizations are advised to upgrade to 15.5.4 HF1 or later, block POST requests with Content-Encoding headers at a WAF or reverse proxy, and limit Serv-U web interface exposure to trusted networks until patching is complete.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-16, Bishop Fox published analysis concluding that CVE-2026-28318 in SolarWinds Serv-U is caused by heap corruption from an invalid free() in an in-memory decompressor, but that the practical impact is denial of service rather than remote code execution. The write-up states the issue can crash the service with a single unauthenticated POST request carrying a Content-Encoding: deflate header and a body.
SolarWinds addressed CVE-2026-28318 in Serv-U 15.5.4 Hotfix 1 by rejecting requests that contain a body and a non-empty Content-Encoding header with HTTP 415 before the body is processed. The references indicate patched systems are build 15.5.4.125 or later.
On 2026-06-12, Bishop Fox published a non-destructive GitHub tool to identify whether a SolarWinds Serv-U host is vulnerable to CVE-2026-28318 without triggering the crash. The script sends a benign POST request with Content-Encoding: identity and treats HTTP 415 as evidence that the HF1 fix is present.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bishopfox.com
Open sourcebishopfox.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.