The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

BleepingComputer reports CISA adding CVE-2026-28318 SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog; NVD and CISA site confirm the details.

Sourcing
1source

via BleepingComputer

BleepingComputer · track record
73Stories
100%Verified
430d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw
VERIFIEDBy Xavier Rivera· ·2 min read

CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw

CISA reported that attackers are exploiting a newly patched high-severity denial-of-service flaw in SolarWinds Serv-U and added the bug to its Known Exploited Vulnerabilities Catalog. Federal agencies must remediate by June 19 while the agency pressed all organizations to implement mitigations against the ongoing attacks immediately.

Source:BleepingComputer
Post
CISA Warns Hackers Exploit Patched SolarWinds Serv-U Flaw
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

CISA adds a patched SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities Catalog after hackers exploit it for unauthenticated denial-of-service attacks that crash servers. Federal agencies must patch by June 19, while thousands of exposed instances and prior Serv-U attacks by ransomware groups heighten risks for all organizations.

The U.S. Cybersecurity and Infrastructure Security Agency reported that threat actors are now exploiting a high-severity denial-of-service vulnerability in SolarWinds Serv-U file transfer software.

CISA adds Serv-U flaw to Known Exploited Vulnerabilities Catalog. Days after the vendor issued a fix, CISA added the bug to its catalog of actively exploited vulnerabilities and directed all Federal Civilian Executive Branch agencies to apply patches by June 19 under Binding Operational Directive 22-01.

Although the directive targets only federal agencies, CISA called on all network defenders in the public and private sectors to address ongoing attacks targeting CVE-2026-28318 without delay.
Remote attackers can exploit the security flaw without privileges in low-complexity attacks that do not require user interaction.

Serv-U vulnerability enables unauthenticated denial-of-service attacks. SolarWinds shipped Serv-U 15.5.4 Hotfix 1 on Thursday to correct the flaw, which arises from uncontrolled resource consumption. The vendor stated the issue allows specially crafted POST requests using "Content-Encoding: deflate" to crash the service without requiring authentication.

Exploitation can occur remotely, without privileges or user interaction, and with low attacker complexity.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
SolarWinds issues temporary mitigations for unpatched systems. The company told administrators unable to install the update immediately to restrict access to trusted IP addresses and to drop any POST request that includes a "content-encoding" header, noting that the affected Serv-U versions do not depend on this feature.

CISA described such bugs as common entry points for malicious actors that create substantial risk to federal networks. The agency recommended following vendor guidance, adhering to BOD 22-01 cloud directives where applicable, or stopping use of the product when fixes cannot be applied.
Over the past several years, CISA has tagged 11 vulnerabilities across various SolarWinds products as actively exploited in attacks, one of which has also been abused by ransomware gangs.

Thousands of Serv-U servers remain exposed online. Shodan lists more than 12,000 internet-facing Serv-U instances, while Shadowserver reports just over 3,100. No data is available on the share that have received the latest patch.

Serv-U flaws repeatedly targeted by multiple threat actors. Multiple criminal and nation-state groups have repeatedly abused Serv-U weaknesses in recent years to exfiltrate corporate and customer information. The Clop ransomware operation leveraged a remote code execution bug in a 2021 intrusion wave, and the Chinese hacking team tracked as DEV-0322 used the same flaw in zero-day attacks that began in July 2021.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
In June 2024, GreyNoise and Rapid7 both identified active exploitation of a separate Serv-U path-traversal vulnerability. Across various SolarWinds offerings, CISA has cataloged 11 exploited vulnerabilities over the past several years, at least one of which ransomware operators have also weaponized.

EXPERT TAKE

Admins should apply the Serv-U 15.5.4 Hotfix 1 without delay or block content-encoding POST requests to prevent unauthenticated remote crashes.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · The Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
CISASolarWindsServ-UVulnerabilityCybersecurity
More fromBleepingComputer
  • OpenAI Acknowledges Partial Outage Hitting ChatGPT Work

    Tech · 3d
  • Carhartt data breach exposes 12.9 million accounts

    Tech · 7d
  • Sakura Internet Hack Exposes Up to 1.36 Million Accounts

    Tech · 15d
More inTech
  • VW Plans 100k Job Cuts, May Halt EV Production at 4 Plants

    Tech · 3h
  • OpenAI GPT-6 Astra Scores 62.7% on ARC-AGI-3

    Tech · 3h
  • Claude, ChatGPT and Grok hit by widespread outage

    Tech · 9h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Free forever.

From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN TECH

VW Plans 100k Job Cuts, May Halt EV Production at 4 Plants

Volkswagen's supervisory board has unanimously approved the Future Plan 2030, which includes an additional 50,000 job cuts worldwide to reach a total of around 100,000 and leaves four German plants without secured future vehicle production after 2031-2034. The move aims to reduce costs and improve competitiveness against Chinese rivals, with alternative uses for the factories to be examined by June 2027.

OpenAI GPT-6 Astra Scores 62.7% on ARC-AGI-3

OpenAI's GPT-6 Astra has posted state-of-the-art scores of 62.7% and 99.9% on ARC-AGI-3 depending on the harness used. The results narrow the measured gap to human-level agentic intelligence on a benchmark designed to track progress toward AGI.

Claude, ChatGPT and Grok hit by widespread outage

Claude, ChatGPT/Codex, and Grok suffered a widespread outage on September 3, 2026 with elevated errors confirmed by OpenAI, Anthropic, and xAI. Services began recovering after about 30 minutes though Grok lagged, coinciding with OpenAI teasing its GPT-6 Astra launch.