Cve 2026 28318
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate.
MITIGATION STEPS: SolarWinds suggests adding the following controls to your web access firewall.
SolarWinds Serv-U 15.5.4 and below
SolarWinds Serv-U 15.5.4 HF1
SolarWinds Serv-U 15.5.4 HF1
CVSS:7.5 /AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
