CVE-2026-28318

SolarWinds Serv-U: Uncontrolled Resource Consumption

As of , CVE-2026-28318 in SolarWinds Serv-U is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.

Exploited
Yes: CISA listed it on 5 June 2026
US federal deadline
19 June 202614 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.02Higher than 79% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: documentation.solarwinds.com and www.solarwinds.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

CISA's description

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

The CVE record's description, from SolarWinds

CVE published
4 June 2026
Assigned by
SolarWinds
CVSS
7.5 High (CVSS 3.1, from the CNA)
CWE-400
Uncontrolled Resource Consumption
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
partial

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Serv-U: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2024-28995Path TraversalSolarWinds Serv-UPatch this weekMetasploit module; EPSS 0.990.99
CVE-2021-35211Remote Code ExecutionSolarWinds Serv-UPatch this weekRansomware use; EPSS 0.910.91
CVE-2021-35247Improper Input ValidationSolarWinds Serv-UPatch soon0.03

Read further