SolarWinds Serv-U file-transfer DoS bug CVE-2026-28318 added to CISA Known Exploited Vulnerabilities catalog
Any organization still running SolarWinds Serv-U file-transfer software can be knocked offline right now. CISA confirmed CVE-2026-28318 is being actively exploited: an unauthenticated attacker crashes the server with a single crafted web request. The fix is Serv-U 15.5.4 HF1.
Any organization still running SolarWinds Serv-U file-transfer software has a problem that needs attention today. CISA has confirmed that a vulnerability tracked as CVE-2026-28318 is being actively exploited in the wild and has added it to its Known Exploited Vulnerabilities catalog. The weakness is a denial-of-service flaw. An attacker with no account and no credentials can send a single specially crafted web request to the Serv-U service and force it to crash. Because Serv-U is widely used to move sensitive files between systems and partners, an outage can interrupt operations and break automated workflows that depend on reliable transfers. The vulnerability carries a severity score of 7.5 out of 10. Under the federal Binding Operational Directive 22-01, civilian agencies were ordered to remediate the flaw by June 19. While that mandate applies only to federal bodies, the same exposure exists for private companies running the software. SolarWinds has released a fix in Serv-U version 15.5.4 HF1. The practical step is simple: confirm which version of Serv-U is running and apply the hotfix without delay. Active exploitation means the gap between disclosure and attack has already closed.