ctipilot.ch

SolarWinds Serv-U uncontrolled resource consumption — unauthenticated DoS via Content-Encoding: deflate (CISA KEV 2026-06-05)

cve · CVE-2026-28318

Coverage timeline
1
first 2026-06-06 → last 2026-06-06
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.1 · see below

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1499.003Endpoint Denial of Service: Application Exhaustion Flood×1

Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications. For example, specific features in web applications may be highly resource intensive. Repeated requests to those features may be able to exhaust system resources and deny access to the application or the server itself.

Evidence: 2026-06-06/cve-2026-28318-solarwinds-serv-u-unauthenticated-dos-added-t · ATT&CK page ↗

Story timeline

  1. 2026-06-06CVE-2026-28318 — SolarWinds Serv-U: unauthenticated DoS added to CISA KEV
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • euvd.enisa.europa.eu1 (50%)
  • solarwinds.com1 (50%)

explore in graph

Entries about SolarWinds Serv-U uncontrolled resource consumption — unauthenticated DoS via Content-Encoding: deflate (CISA KEV 2026-06-05) (1)

2026-06-06 · view entry permalink →

HIGHCVE-2026-28318exploited

CVE-2026-28318 — SolarWinds Serv-U: unauthenticated DoS added to CISA KEV

CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities catalog on 2026-06-05, confirming active exploitation (SolarWinds, 2026-06-04; ENISA EUVD). The flaw is an uncontrolled-resource-consumption issue (CWE-400): an unauthenticated remote attacker sends a crafted HTTP POST carrying Content-Encoding: deflate, triggering decompression memory exhaustion that crashes the Serv-U SFTP/FTP service (T1499.003 Application Exhaustion Flood). On default configurations the service does not auto-restart, so a single request causes a sustained availability outage of the managed-file-transfer endpoint. Fixed in Serv-U 15.5.4 Hotfix 1. Per PD-13, the operational driver here is the confirmed exploitation, not the US BOD 22-01 remediation date: managed-file-transfer appliances are recurrent ransomware-adjacent targets, and an internet-exposed Serv-U that can be knocked offline by one packet is a denial-of-service risk to any process that depends on it. Detection concepts: monitor Serv-U service-process restart/crash events and web-access logs for POST requests with unusual Content-Encoding values.

CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities catalog on 2026-06-05, confirming active exploitation (SolarWinds, 2026-06-04; ENISA EUVD).

ctipilot v2 brief (migrated)
vulnerability06 Jun 05:00Zmulti-sourceOpen finding ↗