Junglewise Threat Intelligence

CVE-2026-28318: SolarWinds Serv-U denial of service via crafted POST request

CVE-2026-28318 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2026-06-04

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U, a widely used file transfer solution, is vulnerable to a denial-of-service attack that can crash the service. An unauthenticated attacker can send a specially crafted web request that exhausts system resources, making the file transfer server unavailable to legitimate users. This can disrupt business operations and automated data exchange processes until the service is manually restarted or patched.

Technical details

A denial-of-service vulnerability exists in SolarWinds Serv-U due to improper handling of compressed data in HTTP POST requests. The flaw is categorized as CWE-400 (Uncontrolled Resource Consumption) and is triggered when the service processes a request containing a 'Content-Encoding: deflate' header. An unauthenticated remote attacker can exploit this by sending a malicious payload that causes the service to crash. This vulnerability has been reported as exploited in the wild. SolarWinds has released Serv-U 15.4.2 Hotfix 1 to address the issue, and mitigation steps are available for environments where immediate patching is not feasible.

Affected products

  • SolarWinds Serv-U Prior to 15.4.2 Hotfix 1

Timeline

  • 2026-06-04: disclosed
  • 2026-06-04: advisory
  • 2026-06-04: exploited: Reported as exploited in the wild in advisory metadata.

Related threats