• News/
  • bleepingcomputer-20260605191530

CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 5, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. Serv-U is the company's Windows and Linux file transfer software that offers Managed File Transfer (MFT) and FTP server capabilities, which allow users to securely exchange files via HTTP/HTTPS, FTP, FTPS, and SFTP. SolarWinds released Serv-U 15.5.4 Hotfix 1 on Thursday to patch this denial-of-service vulnerability (tracked as CVE-2026-28318) and said it stems from an uncontrolled resource consumption weakness. "SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate," the company said. Remote attackers can exploit the security flaw without privileges in low-complexity attacks that don't require user interaction. SolarWinds also advised admins who can't immediately deploy the patch to limit access to known addresses and to block any POST request containing "content-encoding," since the vulnerable Serv-U service does not require this functionality. The Internet intelligence platform Shodan currently tracks over 12,000 Serv-U servers exposed online, and Internet security watchdog Shadowserver just over 3,100, but there is no information on how many have already been patched. ​Days after SolarWinds addressed the vulnerability, CISA flagged it as exploited in the wild and added it to the Known ...

Read full article

Affected Software

1 affected component
SolarWinds Serv-U<15.5.4 Hotfix 1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a high-severity vulnerability in SolarWinds Serv-U software by hackers to crash servers.

2

What security implications are discussed?

The article highlights that the vulnerability poses a significant risk as it allows hackers to crash servers running the affected software.

3

What products or software are affected?

The affected software is SolarWinds Serv-U, which includes file transfer capabilities for Windows and Linux.

4

Who issued the warning about the exploit?

The warning was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

5

When was this exploit first discovered?

The exploit was reported on June 5, 2026, after being recently patched.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203