ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-28318

CRITICAL Export PDF

SolarWinds Serv-U Vulnerability

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

CVSS Score
9.8
CRITICAL
Published
05 Jun 2026 00:00
Modified
N/A
Vendor
SolarWinds
Product
Serv-U
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-400

Affected Systems

SolarWinds
Serv-U
SolarWinds
Serv-U

KEV Status

Known Exploited Vulnerability