PT-2026-46239 · Solarwinds · Serv-U
Published
2026-06-04
·
Updated
2026-06-06
·
CVE-2026-28318
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SolarWinds Serv-U versions prior to 15.5.4 Hotfix 1
Description
SolarWinds Serv-U contains an uncontrolled resource consumption issue that allows an unauthenticated attacker to cause a denial of service. By sending specially crafted POST requests using the
Content-Encoding: deflate header, the Serv-U service can be crashed. Over 12,000 instances are estimated to be exposed worldwide, and real-world exploitation has been observed.Recommendations
Update to version 15.5.4 Hotfix 1.
Apply mitigations provided in the SolarWinds Trust Center if the update cannot be deployed.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Serv-U