Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities Help Net Security

CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)

The vulnerability CVE-2026-28318 (CVSS 7.5) is an uncontrolled resource consumption flaw in SolarWinds Serv-U that allows remote, unauthenticated attackers to cause a denial-of-service condition. Affected versions are Serv-U prior to version 15.5.4. The fixed version is Serv-U 15.5.4, and CISA has mandated federal agencies to apply patches or mitigations by June 19, 2026.
Read Full Article →

A vulnerability (CVE-2026-28318) that can be exploited to crash SolarWinds Serv-U file transfer servers is being leveraged by attackers in the wild, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Friday. The agency has ordered US federal civilian agencies to address it by June 19, 2026, either by implementing a patch or implementing mitigations. About CVE-2026-28318 CVE-2026-28318 is an uncontrolled resource consumption vulnerability that can be triggered by remote, unauthenticated attackers. The flaw … More → The post CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) appeared first on Help Net Security .

Share this article