CVE-2026-28318 — SolarWinds Serv-U: unauthenticated DoS added to CISA KEV
CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities catalog on 2026-06-05, confirming active exploitation (SolarWinds, 2026-06-04; ENISA EUVD). The flaw is an uncontrolled-resource-consumption issue (CWE-400): an unauthenticated remote attacker sends a crafted HTTP POST carrying Content-Encoding: deflate, triggering decompression memory exhaustion that crashes the Serv-U SFTP/FTP service (T1499.003 Application Exhaustion Flood). On default configurations the service does not auto-restart, so a single request causes a sustained availability outage of the managed-file-transfer endpoint. Fixed in Serv-U 15.5.4 Hotfix 1. Per PD-13, the operational driver here is the confirmed exploitation, not the US BOD 22-01 remediation date: managed-file-transfer appliances are recurrent ransomware-adjacent targets, and an internet-exposed Serv-U that can be knocked offline by one packet is a denial-of-service risk to any process that depends on it. Detection concepts: monitor Serv-U service-process restart/crash events and web-access logs for POST requests with unusual Content-Encoding values.
CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities catalog on 2026-06-05, confirming active exploitation (SolarWinds, 2026-06-04; ENISA EUVD).
Defender actions
- Patch SolarWinds Serv-U to 15.5.4 Hotfix 1 if you run it internet-exposed (. Unauthenticated single-request DoS, confirmed exploited; until patched, restrict the SFTP/FTP/HTTP interface exposure.
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.1
Impact TA0040
T1499.003Endpoint Denial of Service: Application Exhaustion Flood
Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications. For example, specific features in web applications may be highly resource intensive. Repeated requests to those features may be able to exhaust system resources and deny access to the application or the server itself.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.