A Crash, Not a Shell: SolarWinds Serv-U CVE-2026-28318
bishopfox.com | vulnerability | High | Actively exploited | CVE-2026-28318 | #active-exploitation | #rce | #vulnerability-research | #denial-of-service | #solarwinds | #serv-u | #cve-2026-28318 | #heap-corruption
Summary
Bishop Fox confirms CVE-2026-28318: one unauthenticated POST with a deflate Content-Encoding crashes SolarWinds Serv-U via heap corruption, but three probed RCE paths dead-end; HF1 fixes it.
- CVSS
- 7.5
- Published
- Collected
Skip to content