Skip to content

Cve 2026 28318

www.solarwinds.com June 9, 2026

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate.

MITIGATION STEPS: SolarWinds suggests adding the following controls to your web access firewall.

SolarWinds Serv-U 15.5.4 and below

SolarWinds Serv-U 15.5.4 HF1

SolarWinds Serv-U 15.5.4 HF1

CVSS:7.5 /AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Extracted Entities

Attack Types (1)