SolarWinds Serv-U Vulnerability
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
CVSS Score
9.8
CRITICAL
Published
05 Jun 2026 00:00
Modified
N/A
Vendor
SolarWinds
Product
Serv-U
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-400
Affected Systems
SolarWinds
Serv-U
SolarWinds
Serv-U
External Links
KEV Status
Known Exploited Vulnerability