discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

CISA added a SolarWinds Serv-U denial-of-service flaw to its KEV catalog after evidence of active exploitation. Federal agencies must fix it by June 19, 2026.

By Ravie Lakshmanan·Jun 6·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
Image: thehackernews.com

CISA says a SolarWinds Serv-U flaw is being actively exploited and has placed it in the KEV catalog. The bug can crash the service through specially crafted requests, and SolarWinds has released a fixed version and mitigation advice.

Why it matters

This matters because KEV additions signal a vulnerability is already being used in the wild, not just discussed in theory. For defenders, it creates an urgent patching and exposure-reduction priority, especially for internet-facing Serv-U deployments.

CISA found a bug in SolarWinds Serv-U that can make the program crash when it gets a tricky web request. It is like a mailbox that can be jammed until it stops working, so agencies now have to patch it fast.

Analysis

What CISA said

CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities catalog after citing evidence that the bug is being actively used. The flaw affects SolarWinds Serv-U multi-protocol file server software and is rated high severity with a CVSS score of 7.5.

What the flaw does

The issue is described as an uncontrolled resource consumption problem that can lead to a denial-of-service condition. SolarWinds said Serv-U can be crashed by specially crafted POST requests sent without authentication, using Content-Encoding: deflate.

Fixes and mitigations

SolarWinds says the issue is addressed in Serv-U version 15.5.4 HF1. As a mitigation, the company recommends limiting access to known addresses and blocking requests containing content-encoding, since the vulnerable service does not need that functionality.

What is still unknown

The article says there are no public details on how the vulnerability is being exploited in real attacks or who is behind the activity. It is also unclear how many internet-exposed Serv-U instances may already be affected.

Government deadline

CISA instructed Federal Civilian Executive Branch agencies to remediate the flaw by June 19, 2026. The article also notes that Serv-U vulnerabilities have been exploited before, including by actors linked to the Cl0p ransomware group.

Key points

  • CISA added CVE-2026-28318 to the KEV catalog because it says the flaw is being actively exploited.
  • The SolarWinds Serv-U bug can cause denial of service by crashing the service under certain conditions.
  • SolarWinds says the issue is fixed in Serv-U version 15.5.4 HF1.
  • The company advises limiting access to known addresses and blocking `content-encoding` requests.
  • CISA gave Federal Civilian Executive Branch agencies a remediation deadline of June 19, 2026.
The Upside

If organizations patch to the fixed Serv-U release and apply the suggested limits, they can reduce the chance of crashes and shrink exposure on internet-facing systems. The KEV listing also gives defenders a clear signal to prioritize this issue quickly.

The Downside

If exposed Serv-U servers stay unpatched, attackers may keep using the flaw to knock them offline. The lack of public detail on the attack method or victim count also leaves defenders with limited visibility into how widespread the abuse may be.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritypolicyregulationunited-statestech

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 6, 2026

Source

thehackernews.com

Share

Topics

securitypolicyregulationunited-statestech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…