CVE Explorer
CVE-2026-28318
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Windows","Linux"],"product":"Serv-U","vendor":"SolarWinds","versions":[{"status":"affected","version":"15.5.4 and previous versions"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3a96f7e9ee606475d9e0c0894ff90b87d981f55d0d1df34959a4af8cbe8d4648 · sha256:93e7ab5f09af9f7f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3a96f7e9ee606475d9e0c0894ff90b87d981f55d0d1df34959a4af8cbe8d4648 · sha256:93e7ab5f09af9f7f… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-400","description":"CWE-400 Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3a96f7e9ee606475d9e0c0894ff90b87d981f55d0d1df34959a4af8cbe8d4648 · sha256:93e7ab5f09af9f7f… · /containers/cna/problemTypes/0/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-400"],"dateAdded":"2026-06-05","dueDate":"2026-06-19","knownRansomwareCampaignUse":"Unknown","notes":"https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318 ; https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4-hotfix-1_release_notes.htm#link7 ; https://nvd.nist.gov/vuln/detail/CVE-2026-28318","product":"Serv-U","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Sol…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:c6dccfbdead8396f430680d58c2a069766ddfedebaecf1c7574daa200f129dfc · sha256:635dff916c4092c0… · /vulnerabilities/48Open source location →
{"cwes":["CWE-400"],"dateAdded":"2026-06-05","dueDate":"2026-06-19","knownRansomwareCampaignUse":"Unknown","notes":"https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318 ; https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4-hotfix-1_release_notes.htm#link7 ; https://nvd.nist.gov/vuln/detail/CVE-2026-28318","product":"Serv-U","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","shortDescription":"Sol…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:277ee4348ea07fb05bd2a2c780f29c89cbb02af237b5c4ea660623c844e9cd72 · sha256:16acee8334e59e44… · /vulnerabilities/45Open source location →
Source references
3 source assertions{"url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4-hotfix-1_release_notes.htm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3a96f7e9ee606475d9e0c0894ff90b87d981f55d0d1df34959a4af8cbe8d4648 · sha256:93e7ab5f09af9f7f… · /containers/cna/references/1
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-28318"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3a96f7e9ee606475d9e0c0894ff90b87d981f55d0d1df34959a4af8cbe8d4648 · sha256:93e7ab5f09af9f7f… · /containers/adp/0/references/0
{"url":"https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28318"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3a96f7e9ee606475d9e0c0894ff90b87d981f55d0d1df34959a4af8cbe8d4648 · sha256:93e7ab5f09af9f7f… · /containers/cna/references/0
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.