Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-cataloginternet-facing-service-vulnerabilitywidely-deployed-product-advisory

CISA Warns Active Exploitation of SolarWinds Serv-U DoS Flaw

Updated 15h agoFirst seen Jun 5, 20265 sources

CISA warned that attackers are actively exploiting SolarWinds Serv-U vulnerability CVE-2026-28318, a recently patched high-severity denial-of-service flaw in the company's managed file transfer and FTP server software for Windows and Linux. The bug can be triggered through low-complexity, unauthenticated POST requests—reported to include the Content-Encoding: deflate header—causing the Serv-U service to crash through uncontrolled resource consumption. CISA has added the issue to its Known Exploited Vulnerabilities catalog and directed Federal Civilian Executive Branch agencies to remediate by June 19 under Binding Operational Directive 22-01.

SolarWinds said the flaw is fixed in Serv-U 15.5.4 Hotfix 1, while CISA urged private-sector organizations to apply mitigations immediately or discontinue use if mitigations are unavailable. Reporting also noted that thousands of Serv-U servers remain exposed online, expanding the potential attack surface. The warning comes amid a broader pattern of SolarWinds Serv-U exploitation, with earlier campaigns tied to the Clop ransomware gang, DEV-0322 Chinese threat actors, and abuse of prior Serv-U vulnerabilities.

Share:
CISA Warns Active Exploitation of SolarWinds Serv-U DoS Flaw
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 5, 20262d ago

CISA adds CVE-2026-28318 to KEV and sets June 19 remediation deadline

CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to remediate the flaw under Binding Operational Directive 22-01. The deadline given to federal agencies was June 19, and CISA also urged private-sector organizations to apply mitigations quickly.

CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers

CISA warns CVE-2026-28318 is being actively exploited

CISA warned that attackers are actively exploiting CVE-2026-28318 in SolarWinds Serv-U to crash vulnerable servers. The agency said the denial-of-service issue can be exploited with low-complexity, unauthenticated POST requests.

CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers

SolarWinds fixes Serv-U vulnerability CVE-2026-28318

SolarWinds released Serv-U 15.5.4 Hotfix 1 to fix CVE-2026-28318, a high-severity denial-of-service flaw caused by uncontrolled resource consumption. The bug affects Serv-U managed file transfer and FTP server software on Windows and Linux and can be triggered with crafted unauthenticated POST requests.

CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.