CVE-2026-28318
SolarWinds Serv-U, serv-u
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
- CVSS
- 7.5
- EPSS
- 8.35% 94.4% percentile
- CISA KEV
- Listed
- Published
- 2026.06.05