SolarWinds Serv-U is affected by CVE-2026-28318, a high-severity unauthenticated denial-of-service flaw in the product’s web interface that has been added to CISA’s Known Exploited Vulnerabilities catalog after active exploitation was confirmed in the wild. The bug can be triggered with a single crafted POST request that includes the Content-Encoding: deflate header and any non-empty body, leading to heap corruption and a crash of the Serv-U process.
Research cited in public reporting found the issue stems from a logic error that bypasses Serv-U’s deflate rejection check when HTTP compression is enabled by default, making the vulnerability a practical crash vector rather than a realistic route to remote code execution. SolarWinds addressed the flaw in Serv-U 15.5.4 HF1 by rejecting requests with a non-empty Content-Encoding header before request-body processing, and defenders were advised they can safely identify patched systems by checking whether a POST request using Content-Encoding: identity returns HTTP 415.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
SolarWinds addressed CVE-2026-28318 in Serv-U 15.5.4 HF1 by rejecting requests with a non-empty Content-Encoding header before processing the request body.
On June 7, 2026, SolarWinds released a security update to fix CVE-2026-28318, an unauthenticated denial-of-service flaw affecting Serv-U 15.5.4 and earlier versions. The update addresses crashes triggered by specially crafted POST requests using the "Content-Encoding: deflate" header.
CISA added CVE-2026-28318, a high-severity unauthenticated denial-of-service flaw in SolarWinds Serv-U, to its Known Exploited Vulnerabilities catalog with active exploitation in the wild confirmed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt.org.eg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.