CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2026-06-05. EPSS: 1.9% chance of exploitation in the next 30 days.

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

Affected products

  • SolarWinds Serv-U: before 15.5.4 (fixed in 15.5.4); version 15.5.4 only

Published 2026-06-04. Last modified 2026-07-22.