CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
CISA added a SolarWinds Serv-U denial-of-service flaw to its KEV catalog after evidence of active exploitation. Federal agencies must fix it by June 19, 2026.
Intelligence analysis by GPT-5.4 Mini

CISA says a SolarWinds Serv-U flaw is being actively exploited and has placed it in the KEV catalog. The bug can crash the service through specially crafted requests, and SolarWinds has released a fixed version and mitigation advice.
CISA found a bug in SolarWinds Serv-U that can make the program crash when it gets a tricky web request. It is like a mailbox that can be jammed until it stops working, so agencies now have to patch it fast.
Analysis
What CISA said
CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities catalog after citing evidence that the bug is being actively used. The flaw affects SolarWinds Serv-U multi-protocol file server software and is rated high severity with a CVSS score of 7.5.
What the flaw does
The issue is described as an uncontrolled resource consumption problem that can lead to a denial-of-service condition. SolarWinds said Serv-U can be crashed by specially crafted POST requests sent without authentication, using Content-Encoding: deflate.
Fixes and mitigations
SolarWinds says the issue is addressed in Serv-U version 15.5.4 HF1. As a mitigation, the company recommends limiting access to known addresses and blocking requests containing content-encoding, since the vulnerable service does not need that functionality.
What is still unknown
The article says there are no public details on how the vulnerability is being exploited in real attacks or who is behind the activity. It is also unclear how many internet-exposed Serv-U instances may already be affected.
Government deadline
CISA instructed Federal Civilian Executive Branch agencies to remediate the flaw by June 19, 2026. The article also notes that Serv-U vulnerabilities have been exploited before, including by actors linked to the Cl0p ransomware group.
Key points
- CISA added CVE-2026-28318 to the KEV catalog because it says the flaw is being actively exploited.
- The SolarWinds Serv-U bug can cause denial of service by crashing the service under certain conditions.
- SolarWinds says the issue is fixed in Serv-U version 15.5.4 HF1.
- The company advises limiting access to known addresses and blocking `content-encoding` requests.
- CISA gave Federal Civilian Executive Branch agencies a remediation deadline of June 19, 2026.
If organizations patch to the fixed Serv-U release and apply the suggested limits, they can reduce the chance of crashes and shrink exposure on internet-facing systems. The KEV listing also gives defenders a clear signal to prioritize this issue quickly.
If exposed Serv-U servers stay unpatched, attackers may keep using the flaw to knock them offline. The lack of public detail on the attack method or victim count also leaves defenders with limited visibility into how widespread the abuse may be.



