cvedb.io
CVE-2026-28318
HIGH · CVSS 7.5 ⚠ KEV — EXPLOITED
EPSS exploitation probability: 95%
⚠ Listed in the CISA Known Exploited Vulnerabilities catalog — actively exploited.
Published 2026-06-05 · Last modified 2026-07-22T20:10:00.127

Summary

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

Affected products

SolarWinds — Serv-U

Does this affect you?

Add your gear to cvedb and we'll alert you only when SolarWinds ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.