CVE-2026-28318

Published Jun 4, 2026

Last updated 4 days ago

Exploit knownCVSS high 7.5
Supply chain
Server
HTTP
Serv-U
SolarWinds Serv-U

Overview

Description
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
Source
psirt@solarwinds.com
NVD status
Analyzed
Products
serv-u

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
Exploit added on
Jun 5, 2026
Exploit action due
Jun 19, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

psirt@solarwinds.com
CWE-400

Social media

Hype score
Not currently trending
  1. 🚨June 2026 Recap 🚨New actively exploited vulnerabilities included: 🔹 CVE-2026-0257 (Palo Alto PAN-OS) 🔹 CVE-2026-45247 (Magento RCE) 🔹 CVE-2026-28318 (SolarWinds Serv-U) 🔹 CVE-2026-50751 (Check Point VPN) 🔹 CVE-2026-20245 (Cisco SD-WAN)

    @CoastalCyberSol

    22 Jun 2026

    4 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🛡️ CVE-2026-28318: Vulnerabilidad DoS en SolarWinds Serv-U explotada activamente sin autenticación Análisis técnico de CVE-2026-28318 en SolarWinds Serv-U: consumo descontrolado de recursos vía POST con deflate permite crashear el servicio sin autenticación.

    @CiberPlanetaOrg

    18 Jun 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🛡️ Alerta de Seguridad: SolarWinds Serv-U Consumo No Controlado de Recursos vía POST sin Autenticación (CVE-2026-28318) SolarWinds Serv-U permite crashear el servicio sin autenticación mediante POST con Content-Encoding: deflate. Explotación activa confirmada. Parchear a

    @CiberPlanetaOrg

    18 Jun 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. After analyzing 60% of vulnerabilities from past week, CVE-2026-28318 has 9 articles published from different internet sources, no other cve has these many articles. More information here: https://t.co/SyyDujjO8C #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    @stooee_

    13 Jun 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Top #CVE to prioritize 👀 - @Android Framework #privesc (CVE-2025-48595) - @SolarWinds Serv-U (CVE-2026-28318) - @Cisco Catalyst SD-WAN Manager (CVE-2026-20245) - @Cisco Unified Communications Manager (CVE-2026-20230) - @Acer Wave 7 routers (CVE-2026-49200/49201) - @UniFi OS

    @stansecure

    10 Jun 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. CISA:パッチによりSolarWinds Serv-UのDoS脆弱性(CVE-2026-28318)が悪用されました CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) #HelpNetSecurity (Jun 8) https://t.co/ieuqowuDdW

    @foxbook

    9 Jun 2026

    217 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 【サイバーセキュリティ動向分析】 トレンドのセキュリティニュース(2026年6月時点) Cisco Catalyst SD-WAN Managerにゼロデイ脆弱性、悪用確認 https://t.co/eZgv9rE6np CISA、SolarWinds Serv-UのDoS脆弱性(CVE-2026-28318)をKEVカ

    @kenebeii

    7 Jun 2026

    164 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Top 5 Trending CVEs: 1 - CVE-2018-17144 2 - CVE-2026-46243 3 - CVE-2026-49975 4 - CVE-2025-49113 5 - CVE-2026-28318 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    7 Jun 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Analyze HIGH-ENGAGEMENT X THREAD 1/4 🚨 Cyber Snapshot: June 6, 2026
CISA flags active SolarWinds Serv-U DoS exploits (CVE-2026-28318) just days after patch. Over 12k servers exposed. Chinese UNC5221 deploys new persistence malware. Cisco SD-WAN zero-day under attack. Patch N

    @seoscottsdale

    6 Jun 2026

    259 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. 1/4 🚨 Cyber Snapshot: June 6, 2026 CISA flags active SolarWinds Serv-U DoS exploits (CVE-2026-28318) just days after patch. Over 12k servers exposed. Chinese UNC5221 deploys new persistence malware. Cisco SD-WAN zero-day under attack. Patch NOW. 🛡️ #CyberSecurity #CISA 2/

    @seoscottsdale

    6 Jun 2026

    104 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Top 5 Trending CVEs: 1 - CVE-2025-48595 2 - CVE-2026-28318 3 - CVE-2026-20245 4 - CVE-2018-17144 5 - CVE-2026-20230 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    6 Jun 2026

    91 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations