CVE-2026-28318
KEV High · CVSS 7.5- CVSS
- 7.5
- nvd
- EPSS
- —
- KEV
- Listed
- 2026-06-05
- Class
- other
- CWE-400
Description
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
References
Status: profiled · ingested 2026-07-23T00:00:18.000Z