Skip to content
Active Exploitation of SolarWinds Serv-U Flaw CVE-2026-28318

Active Exploitation of SolarWinds Serv-U Flaw CVE-2026-28318

First seen 5 Jun 2026, 19:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 6, 2026 at 19:51 UTC
  • CISA warns of active exploitation of CVE-2026-28318 in SolarWinds Serv-U software.
  • The vulnerability allows attackers to crash the service without authentication.
  • Over 12,000 Serv-U servers are currently exposed online, heightening the risk.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of a high-severity vulnerability in SolarWinds Serv-U, tracked as CVE-2026-28318. This flaw allows remote attackers to crash the Serv-U service using specially crafted POST requests without requiring authentication. The vulnerability stems from uncontrolled resource consumption and affects both Windows and Linux versions of Serv-U. SolarWinds released a hotfix (15.5.4 Hotfix 1) on June 4, 2026, to address this issue. CISA has added this CVE to its Known Exploited Vulnerabilities Catalog and mandated that all Federal Civilian Executive Branch agencies patch their servers by June 19, 2026. There are over 12,000 Serv-U servers exposed online, increasing the risk of exploitation. Administrators are advised to limit access to known addresses and block specific POST requests until the patch can be applied.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 97d ago How this analysis works

Timeline

2021-07-14
CVE-2021-35211 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-06-06
CVE-2024-28995 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-04
CVE-2026-28318 published
SolarWinds released a hotfix for a denial-of-service vulnerability in Serv-U, tracked as CVE-2026-28318.
documentation.solarwinds.com
2026-06-05
CISA flags CVE-2026-28318 as exploited
CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities Catalog, urging immediate patching.
Bleepingcomputer
2026-06-05
CISA mandates patching deadline
CISA ordered all Federal Civilian Executive Branch agencies to patch against CVE-2026-28318 by June 19, 2026.
Bleepingcomputer

More articles in this cluster (14)

Following this threat?

Track Clop, Dev-0322 and SolarWinds in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed