SolarWinds Patches Exploited Serv-U Vulnerability
The US cybersecurity agency CISA on Friday warned of attacks targeting a SolarWinds Serv-U vulnerability that had been patched a couple of days earlier.
Tracked as CVE-2026-28318 (CVSS score of 7.5), the bug is described as a denial-of-service (DoS) issue that can be exploited via specially crafted POST requests to crash the Serv-U service.
Successful exploitation of the security defect does not require authentication, SolarWinds warned on Thursday.
The flaw was addressed in Serv-U 15.5.4 Hotfix 1. SolarWinds encourages all customers to download and install the hotfix, including those who recently upgraded to Serv-U 15.5.4.
According to SolarWinds, the hotfix prevents attackers from crashing the Serv-U service via requests containing the ‘Content-Encoding: deflate’ header and some data.
Users of Serv-U versions 15.4.2, 15.5, and 15.5.1, which have reached End-of-Life (EoL), are advised to upgrade to a supported release as soon as possible.
Advertisement. Scroll to continue reading.
While SolarWinds’s advisory...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE