SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
https://www.securityweek.com/solarwinds-patches-exploited-serv-u-vulnerability/
https://thehackernews.com/2026/06/cisa-adds-actively-exploited-solarwinds.html
https://github.com/FCortezSecurity/AVEN
https://github.com/VixianSchool/nuclei-cve-check
https://github.com/BishopFox/CVE-2026-28318-check
https://github.com/jenniferreire26/CVE-2026-28318
https://github.com/johnniebozura31/CVE-2026-28318
https://github.com/cpt-ferna02/AVEN
https://github.com/AJings3c/Threat-Intelligence
https://github.com/cataam-security/cataam
https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28318
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-28318