DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:13:27ZSOURCES: 14CRITICAL: 30
⚠ ACTIVE ALERTS
@FalconFeedsio CRITICAL — 🚨 Ransomware Alert: The Gentlemen RaaS group continues active DLS postings. Now at 478… /// @DarkWebInformer CRITICAL — 🚨 ServiceNow discloses June 5 security update tied to anomalous activity — KB3067321.… /// @MsftSecIntel CRITICAL — MSTIC analysis of The Gentlemen ransomware (tracked internally): self-propagating… /// @GossiTheDog CRITICAL — ServiceNow KB3067321 situation is worse than the vendor comms suggest. Advisory was gated… /// @AlvieriD CRITICAL — The '340M OnlyFans' listing on the leak forum is a compiled corpus — seller confirmed to…
30Critical Threats
15Active CVEs
1IOCs Tracked
14New Advisories
TLP:WHITE
Disclosure not limited. This advisory may be distributed publicly through any channel.
OFFICIAL ADVISORY // KEV-CVE-2026-28318 // PUBLISHED 2026-06-05

CISA KEV: SolarWinds Serv-U Unauthenticated DoS Actively Exploited (CVE-2026-28318)

CISA added CVE-2026-28318 (CVSS 7.5) to its Known Exploited Vulnerabilities catalog on June 5, 2026, confirming active in-the-wild exploitation of an uncontrolled resource consumption flaw in SolarWinds Serv-U file transfer software. Unauthenticated attackers can crash the Serv-U service by sending a specially crafted POST request using the Content-Encoding: deflate HTTP header, with no credentials required. The vulnerability is significant given Serv-U's history of exploitation by ransomware groups (including Cl0p) and nation-state actors, and FCEB agencies must remediate by June 19, 2026.

AFFECTED SYSTEM
SEVERITY
EXPLOIT
PATCH
SolarWinds Serv-U prior to 15.5.4 Hotfix 1
HIGH
LIMITED
PATCHED
SolarWinds Serv-U 15.4.2 (End-of-Life)
HIGH
LIMITED
PATCHED
SolarWinds Serv-U 15.5.0
HIGH
LIMITED
PATCHED
SolarWinds Serv-U 15.5.1 (End-of-Life)
HIGH
LIMITED
PATCHED

Apply SolarWinds Serv-U 15.5.4 Hotfix 1 immediately — this is the only complete fix. As a compensating control, block all HTTP requests containing the 'Content-Encoding' header at the WAF/perimeter layer, as the vulnerable Serv-U service does not require this functionality. Limit network access to Serv-U to known trusted IP ranges. Place Serv-U behind a VPN or reverse proxy with strong authentication where operationally feasible. Users on EoL versions (15.4.2, 15.5, 15.5.1) must upgrade to a supported branch before applying HF1.

Review Serv-U service logs for repeated unexplained service crashes and restarts. Monitor for incoming POST requests with 'Content-Encoding: deflate' headers targeting the Serv-U HTTP listener. Alert on Serv-U process termination events (Windows Event ID 7034/7036 for service stops). Deploy IDPS signatures targeting malformed deflate-encoded POST payloads to Serv-U listener ports (typically TCP 443/8443/22/21). Check SolarWinds Trust Center advisory for any updated IOC indicators.

  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318
  • https://thehackernews.com/2026/06/cisa-adds-actively-exploited-solarwinds.html
  • https://nvd.nist.gov/vuln/detail/CVE-2026-28318
SHARE BRIEF:✕ Post on Xin Share on LinkedIn