CISA Warns of Active Attacks Exploiting SolarWinds Serv-U Vulnerability

The CISA has issued an urgent alert: hackers are actively exploiting a recently patched high-impact vulnerability in SolarWinds Serv-U, causing server crashes. The flaw, identified as CVE-2026-28318, allows denial-of-service attacks without requiring authentication.

Technical Details of the Vulnerability

The flaw resides in an uncontrolled resource consumption issue, specifically in manipulated POST requests with Content-Encoding: deflate. This allows attackers to crash the Serv-U service without elevated privileges and with low operational complexity. SolarWinds has released the Serv-U 15.5.4 Hotfix 1 update to fix the vulnerability.

Mitigation Measures

For organizations that cannot immediately apply the update, SolarWinds recommends limiting access to known addresses and blocking all POST requests containing "content-encoding", as this functionality is not required by the vulnerable service.

Scope of Exposure

According to Shodan, there are currently over 12,000 Serv-U servers exposed online, while Shadowserver records more than 3,100. It is unclear how many of these have already been updated with the security patch.

CISA Response and Deadlines

The CISA has added the vulnerability to its Catalog of Known Exploited Vulnerabilities and ordered civilian federal agencies to apply the patch by June 19, 2026, as required by the Binding Operational Directive (BOD) 22-01. Although this directive applies only to U.S. government agencies, the CISA encourages the private sector to also protect its networks from these attacks.

History of Attacks on Serv-U

Serv-U has repeatedly been targeted by cybercriminal groups and state-sponsored hackers. In 2021, the Clop ransomware group exploited a remote code execution vulnerability (CVE-2021-35211) to breach corporate networks. Additionally, the Chinese group DEV-0322 exploited the same vulnerability in zero-day attacks starting in July 2021.

More recently, in June 2024, cybersecurity firms like GreyNoise and Rapid7 reported that a path traversal vulnerability in Serv-U (CVE-2024-28995) was being actively exploited in attacks.

Business Security Implications

The CISA emphasizes that this type of vulnerability is a common attack vector for malicious actors and poses a significant risk to the entire federal enterprise. Organizations are advised to follow the vendor's instructions to apply mitigations, follow the relevant BOD 22-01 guidelines for cloud services, or stop using the product if mitigations are not available.

History of SolarWinds Vulnerabilities

Over the years, the CISA has identified 11 vulnerabilities in various SolarWinds products as actively exploited in attacks, one of which was abused by ransomware groups. This historical pattern underscores the importance of proactive vulnerability management and rapid response to security alerts.

Importance of Attack Simulations

A recent whitepaper by Picus highlights that security teams detect only 14% of successful attacks, while the remaining 86% go unnoticed. Breach and attack simulations are crucial tools for testing SIEM and EDR rules, ensuring that threats do not evade detection systems.

Recommendations for Security Professionals

In response to this emerging threat, IT security professionals should:

  • Immediately verify if their systems use SolarWinds Serv-U
  • Apply the Serv-U 15.5.4 Hotfix 1 patch as soon as possible
  • Implement the temporary mitigation measures recommended by SolarWinds
  • Closely monitor systems for signs of suspicious activity
  • Consider implementing attack simulations to assess their detection capabilities

Final Considerations

The CISA's alert on the Serv-U vulnerability serves as a critical reminder for organizations of all sizes. Proactive vulnerability management and rapid response to security alerts are essential to protect systems from active attacks. Organizations using Serv-U must act immediately to implement the recommended mitigations and ensure their systems are protected from these emerging threats.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product under Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the misuse of the information published.

In the Crypto sector, every investment involves risks: readers are advised to always inform themselves independently before making any decisions.