DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:13:27ZSOURCES: 14CRITICAL: 30
⚠ ACTIVE ALERTS
@FalconFeedsio CRITICAL β€” 🚨 Ransomware Alert: The Gentlemen RaaS group continues active DLS postings. Now at 478… /// @DarkWebInformer CRITICAL β€” 🚨 ServiceNow discloses June 5 security update tied to anomalous activity β€” KB3067321.… /// @MsftSecIntel CRITICAL β€” MSTIC analysis of The Gentlemen ransomware (tracked internally): self-propagating… /// @GossiTheDog CRITICAL β€” ServiceNow KB3067321 situation is worse than the vendor comms suggest. Advisory was gated… /// @AlvieriD CRITICAL β€” The '340M OnlyFans' listing on the leak forum is a compiled corpus β€” seller confirmed to…
30Critical Threats
15Active CVEs
1IOCs Tracked
14New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-28318PUBLISHED: 2026-06-04
β–  HIGHCVE-2026-28318β˜… CISA KEV LISTED

SolarWinds Serv-U Unauthenticated DoS via Deflate Header

VENDOR: SolarWinds//PRODUCT: Serv-U (MFT / FTP Server)
7.5
HIGH
CVSS 3.1
βœ“
PATCH STATUS
PATCH AVAILABLE
◐
EXPLOIT STATUS
LIMITED EXPLOITATION

An uncontrolled resource consumption flaw (CWE-400) in SolarWinds Serv-U allows an unauthenticated remote attacker to crash the file-transfer service by sending a specially crafted HTTP POST request using the Content-Encoding: deflate header, exhausting system resources during decompression. The crash can be triggered repeatedly without credentials, causing persistent denial of service against FTP/SFTP/HTTP file transfer operations. CISA added to KEV on June 5, 2026, with a federal remediation deadline of June 19, 2026; fixed in Serv-U 15.5.4 Hotfix 1.

β†—
Attack Vector
NETWORK
β–³
Attack Complexity
LOW
⚷
Privs Required
NONE
β—ˆ
User Interaction
NONE
βŠ•
Scope / Impact
UNCHANGED
C:N Β· I:N Β· A:H
AFFECTED VERSIONSAll Serv-U versions prior to 15.5.4; Serv-U 15.5.4 without Hotfix 1 applied
  • β†’ https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318
  • β†’ https://www.helpnetsecurity.com/2026/06/08/cisa-patch-actively-exploited-solarwinds-serv-u-dos-vulnerability-cve-2026-28318/
  • β†’ https://thehackernews.com/2026/06/cisa-adds-actively-exploited-solarwinds.html
  • β†’ https://www.cisa.gov/known-exploited-vulnerabilities-catalog
SHARE BRIEF:βœ• Post on Xin Share on LinkedIn