LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 5, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 19, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities catalog on Jun 5, 2026, with a federal patch deadline of Jun 19, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without…

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that lets an unauthenticated attacker send specially crafted POST requests and crash the service. The issue matters because Serv-U is commonly used for managed file transfer; repeated crashes can interrupt business operations and require manual restarts.

How it works

The weakness is classified as CWE-400, uncontrolled resource consumption. An attacker abuses the flaw by issuing POST requests that include a Content-Encoding: deflate header; the server attempts to process the request in a way that exhausts resources and terminates the Serv-U service. No credentials are required.

Am I affected? How to find it in your systems

SolarWinds Serv-U typically runs as a file-transfer server on Windows or Linux hosts, either on-premises or in cloud deployments. Inventory all installations by checking running processes for Serv-U, reviewing installed software lists, and examining configuration files that define listening ports and virtual hosts. Confirm the exact versions and configurations present against the vendor advisory, because the facts supplied here do not list specific builds. Monitor service logs and system event logs for unexpected Serv-U process terminations that coincide with inbound POST requests containing deflate encoding.

How to remediate

Apply mitigations per the vendor instructions or the update named in the advisory. If the software is deployed as a cloud service, follow applicable BOD 22-01 guidance. If no effective mitigation is available, discontinue use of the product.

If you can't patch immediately

If your data may have been exposed

Actively exploited vulnerabilities lead to breaches. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSolarWinds · Serv-U
WeaknessCWE-400
Added to CISA KEVJun 5, 2026
Federal patch deadlineJun 19, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities