The Cybersecurity and Infrastructure Security Agency has added CVE-2026-28318, an unauthenticated denial-of-service vulnerability in SolarWinds Serv-U, to its Known Exploited Vulnerabilities catalog. This flaw allows remote attackers to crash secure file server platforms using specially crafted HTTP POST requests that exploit the deflate content-encoding header. Security professionals must ensure all affected systems are updated to version 15.5.4 HF1 by June 19, 2026, to prevent service disruptions and mitigate the risk of active exploitation.
Read the full article at Security Affairs
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





