The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

BleepingComputer reports CISA adding CVE-2026-28318 SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog; NVD and CISA site confirm the details.

Sourcing
1source

via BleepingComputer

BleepingComputer · track record
65Stories
100%Verified
2230d
All sources →
Home/Tech/CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw
VERIFIEDBy Xavier Rivera· ·2 min read

CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw

CISA reported that attackers are exploiting a newly patched high-severity denial-of-service flaw in SolarWinds Serv-U and added the bug to its Known Exploited Vulnerabilities Catalog. Federal agencies must remediate by June 19 while the agency pressed all organizations to implement mitigations against the ongoing attacks immediately.

Source:BleepingComputer
Post
CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw
TL;DRAI · 60 sec read

CISA adds a patched SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities Catalog after hackers exploit it for unauthenticated denial-of-service attacks that crash servers. Federal agencies must patch by June 19, while thousands of exposed instances and prior Serv-U attacks by ransomware groups heighten risks for all organizations.

The U.S. Cybersecurity and Infrastructure Security Agency reported that threat actors are now exploiting a high-severity denial-of-service vulnerability in SolarWinds Serv-U file transfer software.

CISA adds Serv-U flaw to Known Exploited Vulnerabilities Catalog. Days after the vendor issued a fix, CISA added the bug to its catalog of actively exploited vulnerabilities and directed all Federal Civilian Executive Branch agencies to apply patches by June 19 under Binding Operational Directive 22-01.

Although the directive targets only federal agencies, CISA called on all network defenders in the public and private sectors to address ongoing attacks targeting CVE-2026-28318 without delay.
Remote attackers can exploit the security flaw without privileges in low-complexity attacks that do not require user interaction.

Serv-U vulnerability enables unauthenticated denial-of-service attacks. SolarWinds shipped Serv-U 15.5.4 Hotfix 1 on Thursday to correct the flaw, which arises from uncontrolled resource consumption. The vendor stated the issue allows specially crafted POST requests using "Content-Encoding: deflate" to crash the service without requiring authentication.

Exploitation can occur remotely, without privileges or user interaction, and with low attacker complexity.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
SolarWinds issues temporary mitigations for unpatched systems. The company told administrators unable to install the update immediately to restrict access to trusted IP addresses and to drop any POST request that includes a "content-encoding" header, noting that the affected Serv-U versions do not depend on this feature.

CISA described such bugs as common entry points for malicious actors that create substantial risk to federal networks. The agency recommended following vendor guidance, adhering to BOD 22-01 cloud directives where applicable, or stopping use of the product when fixes cannot be applied.
Over the past several years, CISA has tagged 11 vulnerabilities across various SolarWinds products as actively exploited in attacks, one of which has also been abused by ransomware gangs.

Thousands of Serv-U servers remain exposed online. Shodan lists more than 12,000 internet-facing Serv-U instances, while Shadowserver reports just over 3,100. No data is available on the share that have received the latest patch.

Serv-U flaws repeatedly targeted by multiple threat actors. Multiple criminal and nation-state groups have repeatedly abused Serv-U weaknesses in recent years to exfiltrate corporate and customer information. The Clop ransomware operation leveraged a remote code execution bug in a 2021 intrusion wave, and the Chinese hacking team tracked as DEV-0322 used the same flaw in zero-day attacks that began in July 2021.
In June 2024, GreyNoise and Rapid7 both identified active exploitation of a separate Serv-U path-traversal vulnerability. Across various SolarWinds offerings, CISA has cataloged 11 exploited vulnerabilities over the past several years, at least one of which ransomware operators have also weaponized.

EXPERT TAKE

Admins should apply the Serv-U 15.5.4 Hotfix 1 without delay or block content-encoding POST requests to prevent unauthenticated remote crashes.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · The Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
CISASolarWindsServ-UVulnerabilityCybersecurity
More fromBleepingComputer
  • CISA warns of actively exploited RCE flaws in Joomla extensions

    Tech · 6d
  • OpenAI Temporarily Drops 5-Hour Cap on GPT-5.6 Sol

    Tech · 7d
  • Progress tells ShareFile on-premises users to power down servers over reported threat

    Tech · 9d
More inTech
  • Xi calls for AI emergency systems and global openness

    Tech · 8h
  • SigNoz 0.133.0 Open Redirect Lets Attackers Steal SSO Tokens

    Tech · 2d
  • Critical Privilege Escalation Flaw Reported in WordPress Plugin Aimogen Pro

    Tech · 2d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Free forever.

MORE IN TECH

Xi calls for AI emergency systems and global openness

Xi Jinping has called for AI openness paired with emergency response systems and new global governance structures, while Asia sees a major Coupang warehouse fire and fresh Indian chip subsidies. The developments highlight competing priorities of innovation, risk control, and regional industrial policy.

SigNoz 0.133.0 Open Redirect Lets Attackers Steal SSO Tokens

SigNoz through 0.133.0 is affected by a reported open redirect in the SSO flow (referenced in NVD as CVE-2026-63094) that lets unauthenticated attackers steal access and refresh tokens from users on Google OAuth, SAML, or OIDC instances. The CVSS 3.1 score of 8.1 from VulnCheck marks it high severity and requires immediate patching on affected self-hosted deployments.

Critical Privilege Escalation Flaw Reported in WordPress Plugin Aimogen Pro

Aimogen Pro for WordPress through version 2.8.4 allows unauthenticated privilege escalation because the aiomatic_call_google_ai_function omits a capability check, letting attackers clear blacklists and run arbitrary PHP such as creating admin accounts. Wordfence rates it critical at CVSS 9.8; the CVE reached NVD on July 17, 2026.