---
schema: 1
kind: vulnerability
title: "CVE-2026-28318 — SolarWinds Serv-U: unauthenticated DoS added to CISA KEV"
headline: "CVE-2026-28318 — SolarWinds Serv-U: unauthenticated DoS added to CISA KEV"
summary: "SolarWinds Serv-U DoS zero-day added to CISA KEV (CVE-2026-28318) — an unauthenticated Content-Encoding: deflate POST crashes the SFTP/FTP service; fixed in Serv-U 15.5.4 Hotfix 1 (SolarWinds, 2026-06-04)."
discovered_at: "2026-06-06T05:00:03Z"
event_date: 2026-06-04
run_id: 2026-06-06-d01b95fe
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - dos
  - pre-auth
  - cisa-kev
  - patch-available
regions:
  - global
sectors:
  - public-sector
  - finance
entities: []
cves:
  - id: CVE-2026-28318
    cvss: "7.5"
    epss: null
    type: dos
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318"
    publisher: SolarWinds Trust Center advisory CVE-2026-28318
    role: primary
  - url: "https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-34268"
    publisher: ENISA EUVD EUVD-2026-34268
    role: corroborating
closed_sources: []
evidence:
  - quote: "CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities catalog on 2026-06-05, confirming active exploitation (SolarWinds, 2026-06-04; ENISA EUVD)."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch SolarWinds Serv-U to 15.5.4 Hotfix 1** if you run it internet-exposed (. Unauthenticated single-request DoS, confirmed exploited; until patched, restrict the SFTP/FTP/HTTP interface exposure."
migrated_from: briefs/2026-06-06.md
---

CISA added CVE-2026-28318 to the Known Exploited Vulnerabilities catalog on 2026-06-05, confirming active exploitation ([SolarWinds, 2026-06-04](https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318); [ENISA EUVD](https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-34268)). The flaw is an uncontrolled-resource-consumption issue (CWE-400): an unauthenticated remote attacker sends a crafted HTTP POST carrying `Content-Encoding: deflate`, triggering decompression memory exhaustion that crashes the Serv-U SFTP/FTP service (`T1499.003` Application Exhaustion Flood). On default configurations the service does not auto-restart, so a single request causes a sustained availability outage of the managed-file-transfer endpoint. Fixed in **Serv-U 15.5.4 Hotfix 1**. Per PD-13, the operational driver here is the confirmed exploitation, not the US BOD 22-01 remediation date: managed-file-transfer appliances are recurrent ransomware-adjacent targets, and an internet-exposed Serv-U that can be knocked offline by one packet is a denial-of-service risk to any process that depends on it. Detection concepts: monitor Serv-U service-process restart/crash events and web-access logs for POST requests with unusual `Content-Encoding` values.
