Security Advisory

CVE-2026-28318

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-04 14:05:58
Last updated 2026-06-06 03:55:57
Assigner SolarWinds
CVSS score not scored
State PUBLISHED

Description

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update