CVE-2026-28318 CRITICAL

SolarWinds Serv-U Vulnerability
Generated: 10 Oct 2026 20:40 • CVE Threat Intelligence

Description

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

9.8
CVSS CRITICAL

Details

Published
05 Jun 2026 00:00
Modified
N/A
Source
CIRCL
Vendor
SolarWinds
Product
Serv-U
Fix Version
Vendor Patch / Mitigation Available