The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. Serv-U is the company's Windows and Linux file transfer software that offers Managed File Transfer (MFT) and FTP server capabilities, which allow users to securely exchange files via HTTP/HTTPS, FTP, FTPS, and SFTP. SolarWinds released Serv-U 15.5.4 Hotfix 1 on Thursday to patch this denial-of-service vulnerability (tracked as CVE-2026-28318) and said it stems from an uncontrolled resource consumption weakness. "SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate," the company said. Remote attackers can exploit the security flaw without privileges in low-complexity attacks that don't require user interaction. SolarWinds also advised admins who can't immediately deploy the patch to limit access to known addresses and to block any POST request containing "content-encoding," since the vulnerable Serv-U service does not require this functionality. The Internet intelligence platform Shodan currently tracks over 12,000 Serv-U servers exposed online, and Internet security watchdog Shadowserver just over 3,100, but there is no information on how many have already been patched. Days after SolarWinds addressed the vulnerability, CISA flagged it as exploited in the wild and added it to the Known ...
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
BleepingComputer
·Sergiu Gatlan
·Published Jun 5, 2026
·Updated
Affected Software
1 affected component
SolarWinds Serv-U<15.5.4 Hotfix 1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of a high-severity vulnerability in SolarWinds Serv-U software by hackers to crash servers.
2
What security implications are discussed?
The article highlights that the vulnerability poses a significant risk as it allows hackers to crash servers running the affected software.
3
What products or software are affected?
The affected software is SolarWinds Serv-U, which includes file transfer capabilities for Windows and Linux.
4
Who issued the warning about the exploit?
The warning was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
5
When was this exploit first discovered?
The exploit was reported on June 5, 2026, after being recently patched.