CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
CISA says attackers are exploiting a patched SolarWinds Serv-U flaw to crash servers. Federal agencies must patch by June 19, and defenders are urged to act now.
Intelligence analysis by GPT-5.4 Mini

CISA has added a recently patched SolarWinds Serv-U denial-of-service bug to its exploited-vulnerabilities list after seeing it used in attacks. The issue lets unauthenticated attackers crash the service with crafted POST requests, and thousands of Serv-U servers are exposed online.
A security bug in a file-sharing server lets attackers send a weird message that makes the server fall over. CISA says that bug is already being used, so anyone running the software needs to fix it fast, like locking a door after finding out someone is trying the handle.
Analysis
What happened
CISA says hackers are now actively exploiting a high-severity flaw in SolarWinds Serv-U, the company’s file transfer product for Windows and Linux. SolarWinds patched the issue in Serv-U 15.5.4 Hotfix 1, describing it as an uncontrolled resource consumption bug that can crash the service when it receives specially crafted POST requests with Content-Encoding: deflate.
The attack does not need authentication, privileges, or user interaction. SolarWinds advised administrators who cannot patch immediately to restrict access to known addresses and block POST requests containing content-encoding, because Serv-U does not need that functionality for normal operation.
Why CISA escalated it
CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to patch by June 19 under Binding Operational Directive 22-01. CISA also urged private-sector defenders to secure exposed systems as soon as possible.
The article notes that Shodan tracks more than 12,000 Serv-U servers exposed online, while Shadowserver sees just over 3,100, though it is unclear how many are already patched. That exposure matters because Serv-U has been a repeated target: the article cites a 2021 remote code execution campaign tied to Clop, zero-day abuse by DEV-0322, and a 2024 path-traversal bug that was also reported as actively exploited.
Key points
- CISA says CVE-2026-28318 is being actively exploited in the wild.
- The bug can crash Serv-U through crafted POST requests using `Content-Encoding: deflate`.
- SolarWinds released Serv-U 15.5.4 Hotfix 1 to fix the issue.
- Federal civilian agencies must patch by June 19 under BOD 22-01.
- The article says more than 12,000 Serv-U servers are exposed online, according to Shodan.
If administrators patch quickly, the attack path disappears for those systems and the crash-only flaw should be much harder to abuse. CISA’s warning may also push organizations to check exposed Serv-U servers sooner rather than later.
Unpatched servers remain exposed to low-complexity attacks that can knock the service offline without login credentials. Because many Serv-U instances are internet-facing, defenders who delay patching may face outages even after the vendor fix is available.



