CISA Known Exploited Vulnerability

CVE-2026-28318

SolarWinds · Serv-U

SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

Date added
BOD 22-01 due date
CWE CWE-400
Ransomware Unknown

CISA description

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.