SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
Is CVE-2026-28318 exploited?
Listed in the CISA KEV catalog on 2026-06-05.
Federal remediation due 2026-06-19.
Past that date by 57 days.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2026-28318
PlainSec has not published a story about this CVE.