discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers

CISA says attackers are exploiting a patched SolarWinds Serv-U flaw to crash servers. Federal agencies must patch by June 19, and defenders are urged to act now.

By Sergiu Gatlan·Jun 5·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
Image: bleepingcomputer.com

CISA has added a recently patched SolarWinds Serv-U denial-of-service bug to its exploited-vulnerabilities list after seeing it used in attacks. The issue lets unauthenticated attackers crash the service with crafted POST requests, and thousands of Serv-U servers are exposed online.

Why it matters

This is an active exploitation alert, not just a theoretical flaw. It affects a widely exposed file-transfer product and now carries a federal patch deadline, which raises the urgency for both government and private-sector defenders.

A security bug in a file-sharing server lets attackers send a weird message that makes the server fall over. CISA says that bug is already being used, so anyone running the software needs to fix it fast, like locking a door after finding out someone is trying the handle.

Analysis

What happened

CISA says hackers are now actively exploiting a high-severity flaw in SolarWinds Serv-U, the company’s file transfer product for Windows and Linux. SolarWinds patched the issue in Serv-U 15.5.4 Hotfix 1, describing it as an uncontrolled resource consumption bug that can crash the service when it receives specially crafted POST requests with Content-Encoding: deflate.

The attack does not need authentication, privileges, or user interaction. SolarWinds advised administrators who cannot patch immediately to restrict access to known addresses and block POST requests containing content-encoding, because Serv-U does not need that functionality for normal operation.

Why CISA escalated it

CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to patch by June 19 under Binding Operational Directive 22-01. CISA also urged private-sector defenders to secure exposed systems as soon as possible.

The article notes that Shodan tracks more than 12,000 Serv-U servers exposed online, while Shadowserver sees just over 3,100, though it is unclear how many are already patched. That exposure matters because Serv-U has been a repeated target: the article cites a 2021 remote code execution campaign tied to Clop, zero-day abuse by DEV-0322, and a 2024 path-traversal bug that was also reported as actively exploited.

Key points

  • CISA says CVE-2026-28318 is being actively exploited in the wild.
  • The bug can crash Serv-U through crafted POST requests using `Content-Encoding: deflate`.
  • SolarWinds released Serv-U 15.5.4 Hotfix 1 to fix the issue.
  • Federal civilian agencies must patch by June 19 under BOD 22-01.
  • The article says more than 12,000 Serv-U servers are exposed online, according to Shodan.
The Upside

If administrators patch quickly, the attack path disappears for those systems and the crash-only flaw should be much harder to abuse. CISA’s warning may also push organizations to check exposed Serv-U servers sooner rather than later.

The Downside

Unpatched servers remain exposed to low-complexity attacks that can knock the service offline without login credentials. Because many Serv-U instances are internet-facing, defenders who delay patching may face outages even after the vendor fix is available.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityunited-statespolicytech

Author

Sergiu Gatlan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 5, 2026

Source

bleepingcomputer.com

Share

Topics

securityunited-statespolicytech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…