Bleepingcomputer Active Exploitation of SolarWinds Serv-U Flaw CVE-2026-28318
Article Content
- •CISA warns of active exploitation of CVE-2026-28318 in SolarWinds Serv-U software.
- •The vulnerability allows attackers to crash the service without authentication.
- •Over 12,000 Serv-U servers are currently exposed online, heightening the risk.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of a high-severity vulnerability in SolarWinds Serv-U, tracked as CVE-2026-28318. This flaw allows remote attackers to crash the Serv-U service using specially crafted POST requests without requiring authentication. The vulnerability stems from uncontrolled resource consumption and affects both Windows and Linux versions of Serv-U. SolarWinds released a hotfix (15.5.4 Hotfix 1) on June 4, 2026, to address this issue. CISA has added this CVE to its Known Exploited Vulnerabilities Catalog and mandated that all Federal Civilian Executive Branch agencies patch their servers by June 19, 2026. There are over 12,000 Serv-U servers exposed online, increasing the risk of exploitation. Administrators are advised to limit access to known addresses and block specific POST requests until the patch can be applied.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track Clop, Dev-0322 and SolarWinds in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies The Cl0p hacking group has claimed to have stolen significant data from nearly 50 companies, including Shell, Philips, General Electric (GE), and Fiserv. The group reported stealing approximately 89GB from Shell and 13.5GB from Philips, including sensitive engineering documents and project plans. The attacks exploit…