CISA Flags SolarWinds Serv-U DoS Bug as Actively Exploited
CVE-2026-28318 crashes the file transfer service. Federal agencies get the usual three-week patch window.

The U.S. Cybersecurity and Infrastructure Security Agency has added a SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog, confirming attackers are already using it in the wild.
The bug is tracked as CVE-2026-28318 and carries a CVSS score of 7.5. It's a denial-of-service issue in the multi-protocol file server that crashes the Serv-U service when triggered.
No remote code execution. No data theft path described in the advisory. Just a service that falls over.
That sounds mild until you remember what Serv-U is used for. Enterprises run it as a managed file transfer endpoint for SFTP, FTPS, and HTTPS workflows — payroll drops, partner EDI feeds, regulated document exchange. When the daemon crashes, those pipelines stop.
Serv-U has a complicated recent history. CVE-2024-28995, a directory traversal flaw, was mass-exploited within days of disclosure last year. And the product line traces back to the same vendor ecosystem hit by the 2020 supply-chain compromise, which is why every Serv-U CVE gets attention it might not otherwise earn.
CISA's KEV listing triggers Binding Operational Directive 22-01. Federal civilian executive branch agencies have a fixed window — typically 21 days from the catalog entry — to patch or pull the affected software off the network. Private sector operators aren't bound by BOD 22-01, but the KEV catalog is the closest thing the U.S. government publishes to a 'patch this now' list, and most mature security programs treat it that way.
Who's exploiting it, and to what end, isn't public. CISA's KEV entries rarely name the actor. A DoS bug being weaponized usually points to one of two things: opportunistic disruption, or a precursor used to force failover into a less hardened path.
There's no mention of ransomware involvement in the catalog entry at this stage.
What Serv-U operators should do
Check the SolarWinds trust center for the fixed build and apply it. If patching has to wait, restrict inbound access to the Serv-U management and file transfer ports to known partner IP ranges, and monitor the service for unexpected restarts or crash dumps — those are the cleanest indicators that someone is throwing the exploit at you.
Log retention matters here. If the service has been crashing and auto-restarting for weeks, you want to know whether that started before or after the KEV listing went live. Pre-dating the public disclosure is the more interesting answer.
U.S. federal agencies running Serv-U should already have a remediation ticket open. Everyone else should treat the BOD 22-01 deadline as their own.



