CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers Severity: High (CVE-2026-28318) CVSS v3.1 Score : 7.5

CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers Severity: High (CVE-2026-28318) CVSS v3.1 Score : 7.5

Information
 
  SolarWinds Serv-U is a widely used, enterprise-grade file transfer software developed by SolarWinds. Operating as a centralized server, it allows organizations, clients, and partners to securely exchange files across both Windows and Linux platforms. The software supports industry-standard secure protocols—including FTP, FTPS, SFTP, and HTTP/HTTPS—offering comprehensive Managed File Transfer (MFT) capabilities that far exceed traditional FTP solutions.

Incident

  The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors have begun actively exploiting a recently patched high-severity vulnerability in SolarWinds Serv-U to disrupt services by sending specially crafted HTTP POST requests.A remote attacker can exploit this vulnerability without authentication or prior access to the target system.

 

  The attack requires low complexity and can cause the Serv-U service to crash, resulting in a denial-of-service (DoS) condition.Because Serv-U is widely used by large enterprises, healthcare organizations, and government agencies for transferring sensitive files—including financial records, confidential documents, and customers' personal information—it remains an attractive target for cybercriminals. Threat actors frequently monitor Serv-U for security weaknesses that can be leveraged to disrupt business operations, steal sensitive data, or deploy ransomware. In cases where more severe vulnerabilities enable remote code execution,

  attackers may also use the compromised server as an entry point to gain access to an organization's internal network.SolarWinds has advised administrators who are unable to immediately apply the security update to restrict access to the Serv-U server to trusted IP addresses only and, where possible, block malicious or unnecessary HTTP POST requests as a temporary mitigation measure.CISA has since added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that it is being actively exploited in the wild. The agency has also directed all U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate the vulnerability by applying the appropriate security updates no later than June 19, in accordance with the requirements of the Binding Operational Directive (BOD) 22-01.

Affected Products and Versions

  • SolarWinds Serv-U version 15.5.4 and all prior versions are affected.

Recommendation

  • Upgrade Serv-U to version 15.5.4 Hotfix 1.
  • Implement network access controls to limit exposure to trusted sources.
  • Continuously monitor logs and security events for indicators of compromise.
  • Configure WAF/Firewall rules to block HTTP POST requests containing the Content-Encoding header.

The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)

References

Weekly Interesting CVE

NO.

CVE Name

Published Date

Last Update

Device/Appplication/OS Target

Attack Type

CVSS
Severity Rating

Detail

Solution

Reference

1

CVE-2026-10187

31/5/2026

31/5/2026

Totolink N300RH

Stack-Based Buffer Overflow

9.3

A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

No vendor fix or workaround currently provided.

https://app.opencve.io/cve/CVE-2026-10187

 

 

2

CVE-2025-12686

27/5/2026

27/5/2026

Synology

Buffer Overflow

9.8

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors

No vendor fix or workaround currently provided.

https://www.synology.com/en-global/security/advisory/Synology_SA_25_12

 

3

CVE-2026-46833

28/5/2026

29/5/2026

Oracle
Net Service, Database Server
affected from 23.4.0 through 23.26.2

Remote Code Execution

7.5

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Net Service.

Apply the latest security patches.

https://app.opencve.io/cve/CVE-2026-46833

 4

CVE-2026-42731

27/5/2026

27/5/2026

WordPress miniorange otp verification
version <= 5.4.9

Privilege Escalation

9.8

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation

Update to version 5.5.0 or later to resolve the vulnerability.

https://www.cve.org/CVERecord?id=CVE-2026-42731
https://patchstack.com/database/Wordpress/Plugin/miniorange-otp-verification/vulnerability/wordpress-miniorange-otp-verification-plugin-5-4-9-privilege-escalation-vulnerability?_s_id=cve

5

CVE-2026-9955

28/5/2026

28/5/2026

Google Chrome on iOS
prior to 148.0.7778.216

Cross-domain policy

-

nappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Update to version 148.0.7778.216 or later to resolve the vulnerability.

https://www.cve.org/CVERecord?id=CVE-2026-9955

 

Malware News or Campaign IOC/IOA | EN

No

Campaign Name

Detection Date

Attack

Type

 

Description

 

Mitigation/Remediation

1

New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

01/06/2026

Phishing, Supply Chain Attack,

A new vulnerability was discovered in the Linux kernel, which remains exploitable despite partial fixes. The PAN‑OS GlobalProtect (CVE‑2026‑0257) flaw has already been actively exploited; PAN‑OS is the operating system powering Palo Alto Networks firewalls that manage network access and VPNs, meaning such vulnerabilities directly impact enterprise security. A severe Gogs vulnerability allows attackers to execute commands on servers, with no patch available yet. Meanwhile, attackers are increasingly using AI‑generated phishing kits and complex payloads, as well as OAuth phishing that tricks users into granting access without realizing it.Impact: Organizations using PAN‑OS/Prisma Access risk system compromise, Gogs administrators face repository takeover and credential leaks, Linux users must closely follow kernel updates, and all organizations are exposed to phishing campaigns leveraging AI and OAuth.

  • Update patches for Linux and PAN‑OS to the latest versions immediately
  • Review and disable authentication override cookies, and ensure strict certificate validation in PAN‑OS
  • Train users to recognize OAuth phishing and always verify application permission requests

Ref: https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html

09 June 2026

Viewed 182 time

Engine by shopup.com