INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
CISA Adds SolarWinds Serv-U Flaw to Known Exploited Vulnerabilities Catalog
| 2026-06-06 21:44 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On June 6, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SolarWinds Serv-U flaw, tracked as CVE-2026-28318 with a CVSS score of 7.5, to its Known Exploited Vulnerabilities catalog. The identified entity behind this incident is not specified in either source. This vulnerability affects approximately 15.5.4 and earlier versions of the SolarWinds Serv-U platform, which can be exploited by sending specially crafted HTTP POST requests using the Content-Encoding: deflate header, causing the service to crash without requiring valid credentials. Successful exploitation can disrupt file transfer operations and make the service unavailable to legitimate users; experts recommend applying security updates as soon as possible or implementing mitigation measures through the SolarWinds Trust Center.
Technical Mitigations AI-generated
• Limit access to known addresses and block any request containing "content-encoding" since the vulnerable service does not require this functionality.
• Block requests with a specially crafted HTTP POST request using the Content-Encoding: deflate header, as it causes the Serv-U service to crash without requiring valid credentials.
• Apply SolarWinds Serv-U 15.5.4 HF1 or later patches to address the vulnerability and prevent exploitation by hackers.
• Note that there is no clear indication of a specific technique to detect in this case, but rather mitigation measures for known vulnerabilities.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-28995CVE-2024-28995
CVE-2021-35211CVE-2021-35211
CVE-2026-28318CVE-2026-28318
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
2026/06/06
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the high-severity SolarWinds Serv-U flaw, tracked as CVE-2026-28318 with a CVSS score of 7.5, to its Known Exploited Vulnerabilities catalog after it was flagged as exploited in the wild by SolarWinds.
Click on any entity below to view its context and source!
infrastructure
15.5.4
SolarWinds released Serv-U 15.5.4 Hotfix 1
on Thursday
to patch this denial-of-service vulnerability (tracked as
CVE-2026-28318
) and said it stems from an uncontrolled resource consumption weakness.
The issue has been addressed in SolarWinds Serv-U version 15.5.4 HF1.
infrastructure
Windows
Serv-U is the company's Windows and Linux file transfer software that offers Managed File Transfer (MFT) and FTP server capabilities, which allow users to securely exchange files via HTTP/HTTPS, FTP, FTPS, and SFTP.
infrastructure
Linux
Serv-U is the company's Windows and Linux file transfer software that offers Managed File Transfer (MFT) and FTP server capabilities, which allow users to securely exchange files via HTTP/HTTPS, FTP, FTPS, and SFTP.
infrastructure
12,000 U servers
The Internet intelligence platform Shodan currently
tracks over 12,000 Serv-U servers exposed online,
and Internet security watchdog Shadowserver
just over 3,100
, but there is no information on how many have already been patched.
infrastructure
3,100 watchdog Shadowserver
The Internet intelligence platform Shodan currently
tracks over 12,000 Serv-U servers exposed online,
and Internet security watchdog Shadowserver
just over 3,100
, but there is no information on how many have already been patched.
Tactical Metrics
Metrics
infrastructure
15.5.4
Software Version
Click for context!
The issue has been addressed in SolarWinds Serv-U version 15.5.4 HF1.
SolarWinds released Serv-U 15.5.4 Hotfix 1
on Thursday
to patch this denial-of-service vulnerability (tracked as
CVE-2026-28318
) and said it stems from an uncontrolled resource consumption weakness.
Metrics
infrastructure
Windows
Affected Product
Serv-U is the company's Windows and Linux file transfer software that offers Managed File Transfer (MFT) and FTP server capabilities, which allow users to securely exchange files via HTTP/HTTPS, FTP, FTPS, and SFTP.
Metrics
infrastructure
Linux
Affected Product
Serv-U is the company's Windows and Linux file transfer software that offers Managed File Transfer (MFT) and FTP server capabilities, which allow users to securely exchange files via HTTP/HTTPS, FTP, FTPS, and SFTP.
Metrics
infrastructure
12,000
U Servers
The Internet intelligence platform Shodan currently
tracks over 12,000 Serv-U servers exposed online,
and Internet security watchdog Shadowserver
just over 3,100
, but there is no information on how many have already been patched.
Metrics
infrastructure
3,100
Watchdog Shadowserver
The Internet intelligence platform Shodan currently
tracks over 12,000 Serv-U servers exposed online,
and Internet security watchdog Shadowserver
just over 3,100
, but there is no information on how many have already been patched.
Intelligence Sources
The Hacker News
2026-06-06
Security Affairs
2026-06-06
BleepingComputer
2026-06-05
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
organisation
Identified Entity
SolarWinds Serv-U
entity
16x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
9x
timeline
Temporal Reference
June 19, 2026
date
3x
vulnerability
Exploited CVE
CVE-2026-28318
cve
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
infrastructure
Affected Product
Windows
software
2x
general metric
%
54
%
Contextual Telemetry
Context Block
11 METRICS
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Score
3
score
general metric
Vulnerability
8
vulnerability
infrastructure
Software Version
15.5.4
version
general metric
Jun
6
jun
industry
Targeted Sector
Government
sector
general metric
Vulnerabilities
11
vulnerabilities
general metric
15.5.4 Hotfix
1
15.5.4 hotfix
source region
Origin Country
China
country
infrastructure
U Servers
12,000
u servers
infrastructure
Watchdog Shadowserver
3,100
watchdog shadowserver
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.