CVE-2026-28318

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

Scoring

Severity
HIGH
CVSS base score
7.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS probability
40.01%
CISA KEV
Known exploited vulnerability
CWE
CWE-400
Published
2026-06-04
Last modified
2026-06-06

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs