PT-2026-46239 · Solarwinds · Serv-U

CVE-2026-28318

·

Published

2026-06-03

·

Updated

2026-07-03

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SolarWinds Serv-U versions prior to 15.5.4 Hotfix 1
Description SolarWinds Serv-U is susceptible to uncontrolled resource consumption when processing compressed HTTP request bodies. An unauthenticated remote attacker can trigger a denial-of-service condition, causing the service to crash, by sending a specially crafted POST request to the web interface. The attack utilizes a decompression bomb via the Content-Encoding header set to deflate, which forces the system to exhaust CPU and memory resources during decompression before authentication occurs.
There are over 12,000 instances of Serv-U exposed to the internet. This issue has been confirmed as actively exploited in the wild.
Recommendations Update to SolarWinds Serv-U 15.5.4 Hotfix 1. Restrict access to the Serv-U web interface to trusted IP addresses. Block all requests containing the Content-Encoding header, as the software does not utilize this functionality. Monitor web and application logs for anomalous POST requests and sudden spikes in CPU or RAM usage by the Serv-U process.

Fix

RCE

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07860
CVE-2026-28318

Affected Products

Serv-U