The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

BleepingComputer reports CISA adding CVE-2026-28318 SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog; NVD and CISA site confirm the details.

Sourcing
1source

via BleepingComputer

BleepingComputer · track record
78Stories
100%Verified
230d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw
VERIFIEDBy Xavier Rivera· ·2 min read

CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw

CISA reported that attackers are exploiting a newly patched high-severity denial-of-service flaw in SolarWinds Serv-U and added the bug to its Known Exploited Vulnerabilities Catalog. Federal agencies must remediate by June 19 while the agency pressed all organizations to implement mitigations against the ongoing attacks immediately.

Source:BleepingComputer
Post
CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

CISA adds a patched SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities Catalog after hackers exploit it for unauthenticated denial-of-service attacks that crash servers. Federal agencies must patch by June 19, while thousands of exposed instances and prior Serv-U attacks by ransomware groups heighten risks for all organizations.

The U.S. Cybersecurity and Infrastructure Security Agency reported that threat actors are now exploiting a high-severity denial-of-service vulnerability in SolarWinds Serv-U file transfer software.

CISA adds Serv-U flaw to Known Exploited Vulnerabilities Catalog. Days after the vendor issued a fix, CISA added the bug to its catalog of actively exploited vulnerabilities and directed all Federal Civilian Executive Branch agencies to apply patches by June 19 under Binding Operational Directive 22-01.

Although the directive targets only federal agencies, CISA called on all network defenders in the public and private sectors to address ongoing attacks targeting CVE-2026-28318 without delay.
Remote attackers can exploit the security flaw without privileges in low-complexity attacks that do not require user interaction.

Serv-U vulnerability enables unauthenticated denial-of-service attacks. SolarWinds shipped Serv-U 15.5.4 Hotfix 1 on Thursday to correct the flaw, which arises from uncontrolled resource consumption. The vendor stated the issue allows specially crafted POST requests using "Content-Encoding: deflate" to crash the service without requiring authentication.

Exploitation can occur remotely, without privileges or user interaction, and with low attacker complexity.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
SolarWinds issues temporary mitigations for unpatched systems. The company told administrators unable to install the update immediately to restrict access to trusted IP addresses and to drop any POST request that includes a "content-encoding" header, noting that the affected Serv-U versions do not depend on this feature.

CISA described such bugs as common entry points for malicious actors that create substantial risk to federal networks. The agency recommended following vendor guidance, adhering to BOD 22-01 cloud directives where applicable, or stopping use of the product when fixes cannot be applied.
Over the past several years, CISA has tagged 11 vulnerabilities across various SolarWinds products as actively exploited in attacks, one of which has also been abused by ransomware gangs.

Thousands of Serv-U servers remain exposed online. Shodan lists more than 12,000 internet-facing Serv-U instances, while Shadowserver reports just over 3,100. No data is available on the share that have received the latest patch.

Serv-U flaws repeatedly targeted by multiple threat actors. Multiple criminal and nation-state groups have repeatedly abused Serv-U weaknesses in recent years to exfiltrate corporate and customer information. The Clop ransomware operation leveraged a remote code execution bug in a 2021 intrusion wave, and the Chinese hacking team tracked as DEV-0322 used the same flaw in zero-day attacks that began in July 2021.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
In June 2024, GreyNoise and Rapid7 both identified active exploitation of a separate Serv-U path-traversal vulnerability. Across various SolarWinds offerings, CISA has cataloged 11 exploited vulnerabilities over the past several years, at least one of which ransomware operators have also weaponized.

EXPERT TAKE

Admins should apply the Serv-U 15.5.4 Hotfix 1 without delay or block content-encoding POST requests to prevent unauthenticated remote crashes.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
CISASolarWindsServ-UVulnerabilityCybersecurity
More fromBleepingComputer
  • Denmark CPR breach exposes data of 8.8 million people

    Tech · 3d
  • Microsoft Rolls Out Windows 11 2026 Update as Small Enablement Package

    Tech · 9d
  • OpenAI confirms GPT-6 Astra reaches Critical cybersecurity threshold

    Tech · 1mo
More inTech
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 8h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 11h
  • Bloomberg: Apple plans first touchscreen MacBook Pros for October 27

    Tech · 14h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.

  • Tech· 

    Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.

  • Tech· 

    Critical CVE-2026-16823 hits IBM Security Verify Access

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 contain critical authentication bypass flaw CVE-2026-16823. The NVD rates it 9.1 and warns of remote exploitation without credentials.

  • Tech· 

    Anthropic Launches Cyber Mission to Secure Infrastructure and Open-Source Code

    Anthropic has launched the Anthropic Cyber Mission to support defenders of critical infrastructure and open-source software with models, engineers, and tools. The initiative starts with the Critical Infrastructure Defense Program and free OSS Scanner amid ongoing challenges in verifying and fixing vulnerabilities.