CVE 7.5 HIGH

SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability_CVE-2026-28318

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

Basic Information

ID CVE-2026-28318
Source SolarWinds
Published Jun 4, 2026 at 14:05

Affected Product

Vendor SolarWinds
Product Serv-U
Version 15.5.4 and previous versions
Affected Versions SolarWinds Serv-U 15.5.4 and previous versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.