Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

A Crash, Not a Shell: SolarWinds Serv-U CVE-2026-28318

bishopfox.com | vulnerability | High | Actively exploited | CVE-2026-28318 | #active-exploitation | #rce | #vulnerability-research | #denial-of-service | #solarwinds | #serv-u | #cve-2026-28318 | #heap-corruption

Summary

Bishop Fox confirms CVE-2026-28318: one unauthenticated POST with a deflate Content-Encoding crashes SolarWinds Serv-U via heap corruption, but three probed RCE paths dead-end; HF1 fixes it.
CVSS
7.5
Published
Collected

original ↗

Related coverage

back