The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMENEWSFEEDEVENTS
—STORIES—VERIFIED
BOOKMARKS
RSSSOURCESABOUTCORRECTIONS
RSS
© 2026 The Circuitry
About UsContactCorrections
  • Home
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

BleepingComputer reports CISA adding CVE-2026-28318 SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog; NVD and CISA site confirm the details.

Sourcing
1source

via BleepingComputer

BleepingComputer · track record
24Stories
100%Verified
1930d
All sources →
Home/Tech
VERIFIEDBy Xavier Rivera· ·2 min read

CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw

CISA warned that hackers are actively exploiting a recently patched high-severity flaw in SolarWinds Serv-U software to crash servers and added it to its Known Exploited Vulnerabilities Catalog. The agency ordered federal agencies to patch by June 19 and urged all organizations to mitigate the ongoing attacks immediately.

Source:BleepingComputer
Post
CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw
TL;DRAI · 60 sec read

CISA adds a patched SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities Catalog after hackers exploit it for unauthenticated denial-of-service attacks that crash servers. Federal agencies must patch by June 19, while thousands of exposed instances and prior Serv-U attacks by ransomware groups heighten risks for all organizations.

CISA warned that hackers are actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. The vulnerability is tracked as CVE-2026-28318.

CISA adds Serv-U flaw to Known Exploited Vulnerabilities Catalog. Days after SolarWinds addressed the vulnerability, CISA flagged it as exploited in the wild and added it to the catalog. The agency ordered all Federal Civilian Executive Branch agencies to patch their servers by June 19 as mandated by Binding Operational Directive 22-01.

While the directive applies only to U.S. government agencies, CISA urged all network defenders including the private sector to secure networks against ongoing CVE-2026-28318 attacks as soon as possible.
Remote attackers can exploit the security flaw without privileges in low-complexity attacks that do not require user interaction.
Serv-U vulnerability enables unauthenticated denial-of-service attacks. SolarWinds released Serv-U 15.5.4 Hotfix 1 on Thursday to patch the denial-of-service vulnerability stemming from an uncontrolled resource consumption weakness. The company said Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate.

Remote attackers can exploit the security flaw without privileges in low-complexity attacks that do not require user interaction.

SolarWinds issues temporary mitigations for unpatched systems. SolarWinds advised admins who cannot immediately deploy the patch to limit access to known addresses. The company also recommended blocking any POST request containing "content-encoding" since the vulnerable Serv-U service does not require this functionality.

CISA warned that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. It advised applying mitigations per vendor instructions, following applicable BOD 22-01 guidance for cloud services, or discontinuing use of the product if mitigations are unavailable.
Over the past several years, CISA has tagged 11 vulnerabilities across various SolarWinds products as actively exploited in attacks, one of which has also been abused by ransomware gangs.
Thousands of Serv-U servers remain exposed online. The Internet intelligence platform Shodan currently tracks over 12,000 Serv-U servers exposed online. Internet security watchdog Shadowserver tracks just over 3,100.

There is no information on how many have already been patched.

Serv-U flaws repeatedly targeted by multiple threat actors. In recent years, multiple cybercrime and state-backed hacking groups have targeted vulnerabilities in Serv-U to steal sensitive corporate and customer data. For instance, the Clop ransomware gang exploited a Serv-U remote code execution vulnerability in a 2021 campaign while DEV-0322 Chinese hackers deployed exploits in zero-day attacks starting in July 2021.

More recently in June 2024, GreyNoise and Rapid7 tagged a Serv-U path-traversal vulnerability as actively exploited. Over the past several years, CISA has tagged 11 vulnerabilities across various SolarWinds products as actively exploited in attacks, one of which has also been abused by ransomware gangs.

EXPERT TAKE

Admins should apply the Serv-U 15.5.4 Hotfix 1 without delay or block content-encoding POST requests to prevent unauthenticated remote crashes.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
CoffeeSupport →Follow@thecircuitry_ →

Reader-supported · Daily Brief

Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.

HELP US IMPROVE

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Support →
CISASolarWindsServ-UVulnerabilityCybersecurity
More fromBleepingComputer
  • DentaQuest Breach Exposes Data of 2.6 Million Accounts

    Tech · 1d
  • Microsoft Exchange Online Outage Hits Mail Flow in North America and Germany

    Tech · 4d
  • Google Fixes Actively Exploited Android Zero-Day in June Patches

    Tech · 4d
More inTech
  • S&P 500 Rejects Fast-Track for SpaceX and AI Firms

    Tech · 22h
  • New York Passes One-Year Moratorium on New Large Data Centers

    Tech · 1d
  • Amazon Leo to Launch Record Ariane 6 Payload of 36 Satellites

    Tech · 1d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Daily brief at 7 AM ET. Top tech stories, every morning.

MORE IN TECH

S&P 500 Rejects Fast-Track for SpaceX and AI Firms

S&P Dow Jones Indices refused to waive seasoning, profitability, or public float rules for SpaceX's IPO, blocking accelerated S&P 500 entry that could have unlocked billions in passive funds. The same barriers now apply to expected IPOs from OpenAI and Anthropic, limiting exposure of retirement assets to unprofitable AI bets.

New York Passes One-Year Moratorium on New Large Data Centers

New York lawmakers approved a one-year moratorium on new large data centers, the first such statewide measure if signed by Governor Hochul. The pause aims to study environmental and energy impacts amid growing AI-driven demand.

Amazon Leo to Launch Record Ariane 6 Payload of 36 Satellites

Amazon's LE-03 mission will deploy a record 36 Leo satellites on Ariane 6 using upgraded P160C boosters, marking the heaviest payload ever for an Ariane rocket. The launch advances the constellation past 330 satellites already in orbit while delivering €2.8 billion in projected EU GDP impact and supporting thousands of jobs.