INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

CISA Adds SolarWinds Serv-U Flaw to Known Exploited Vulnerabilities Catalog

| 2026-06-06 21:44 HIGH HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On June 6, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SolarWinds Serv-U flaw, tracked as CVE-2026-28318 with a CVSS score of 7.5, to its Known Exploited Vulnerabilities catalog. The identified entity behind this incident is not specified in either source. This vulnerability affects approximately 15.5.4 and earlier versions of the SolarWinds Serv-U platform, which can be exploited by sending specially crafted HTTP POST requests using the Content-Encoding: deflate header, causing the service to crash without requiring valid credentials. Successful exploitation can disrupt file transfer operations and make the service unavailable to legitimate users; experts recommend applying security updates as soon as possible or implementing mitigation measures through the SolarWinds Trust Center.
Technical Mitigations AI-generated
• Limit access to known addresses and block any request containing "content-encoding" since the vulnerable service does not require this functionality. • Block requests with a specially crafted HTTP POST request using the Content-Encoding: deflate header, as it causes the Serv-U service to crash without requiring valid credentials. • Apply SolarWinds Serv-U 15.5.4 HF1 or later patches to address the vulnerability and prevent exploitation by hackers. • Note that there is no clear indication of a specific technique to detect in this case, but rather mitigation measures for known vulnerabilities.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-28995CVE-2024-28995 CVE-2021-35211CVE-2021-35211 CVE-2026-28318CVE-2026-28318
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎2026/06/06
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the high-severity SolarWinds Serv-U flaw, tracked as CVE-2026-28318 with a CVSS score of 7.5, to its Known Exploited Vulnerabilities catalog after it was flagged as exploited in the wild by SolarWinds.
infrastructure 15.5.4
infrastructure Windows
infrastructure Linux
infrastructure 12,000 U servers
infrastructure 3,100 watchdog Shadowserver
Tactical Metrics
Metrics
infrastructure
‎15.5.4
Software Version
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
12,000
U Servers
Metrics
infrastructure
3,100
Watchdog Shadowserver
Intelligence Sources