
CISA Flags SolarWinds Serv-U DoS Flaw as Actively Exploited — Federal Deadline Is June 19
A denial-of-service vulnerability in SolarWinds Serv-U lets unauthenticated attackers crash file transfer servers with a single malformed POST request. CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities catalog on June 5 with a federal remediation deadline of June 19. The fix is in Serv-U 15.5.4 HF1.










