CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
CISA has issued a warning about hackers actively exploiting a recently patched vulnerability in SolarWinds Serv-U, a file transfer software, to crash servers. This vulnerability, CVE-2026-28318, stems from uncontrolled resource consumption and allows attackers to cause denial-of-service attacks without authentication. The alert highlights the ongoing risk to organizations and emphasizes the importance of timely patching and mitigation strategies.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a concerning trend: hackers are leveraging a previously patched vulnerability in SolarWinds Serv-U to disrupt server operations. This vulnerability, CVE-2026-28318, allows attackers to trigger denial-of-service attacks by sending specially crafted POST requests, bypassing the need for user credentials. SolarWinds addressed this issue with a hotfix released on Thursday, but the ongoing exploitation underscores the critical need for rapid deployment of security updates. CISA’s response, including a Binding Operational Directive (BOD) 22-01, mandates patching for all Federal Civilian Executive Branch agencies by June 19th, highlighting the severity of the threat to the federal enterprise.