CISA Flags Active Exploitation of SolarWinds Serv-U DoS Flaw
CISA has confirmed active in-the-wild exploitation of CVE-2026-28318, a high-severity unauthenticated denial-of-service flaw in SolarWinds Serv-U file transfer software, and added it to the Known Exploited Vulnerabilities Catalog. SolarWinds has released Serv-U 15.5.4 Hotfix 1, with US Federal Civilian Executive Branch agencies facing a June 19, 2026 patch deadline. Internet-exposure estimates diverge between Shodan (~12,000) and Shadowserver (~3,100). Observed exploitation remains confined to DoS, with no confirmed data exfiltration, ransomware deployment, or named insured losses reported to date.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Low impact. CVE-2026-28318 is an unauthenticated denial-of-service weakness that crashes Serv-U servers via crafted POST requests with Content-Encoding headers; it is not a confirmed data exfiltration or ransomware vector. No named insured assets are confirmed affected, no credible loss estimates exist, and no claims, reserving, or underwriting actions are evidenced. Historical Serv-U exploitation by groups such as Clop warrants continued monitoring, but current evidence keeps the event below the concrete London Market loss-pathway threshold while warranting cyber underwriter portfolio awareness given the installed base of Serv-U among insured enterprises.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialLloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts