CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers Severity: High (CVE-2026-28318) CVSS v3.1 Score : 7.5
Information
SolarWinds Serv-U is a widely used, enterprise-grade file transfer software developed by SolarWinds. Operating as a centralized server, it allows organizations, clients, and partners to securely exchange files across both Windows and Linux platforms. The software supports industry-standard secure protocols—including FTP, FTPS, SFTP, and HTTP/HTTPS—offering comprehensive Managed File Transfer (MFT) capabilities that far exceed traditional FTP solutions.
Incident
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors have begun actively exploiting a recently patched high-severity vulnerability in SolarWinds Serv-U to disrupt services by sending specially crafted HTTP POST requests.A remote attacker can exploit this vulnerability without authentication or prior access to the target system.
The attack requires low complexity and can cause the Serv-U service to crash, resulting in a denial-of-service (DoS) condition.Because Serv-U is widely used by large enterprises, healthcare organizations, and government agencies for transferring sensitive files—including financial records, confidential documents, and customers' personal information—it remains an attractive target for cybercriminals. Threat actors frequently monitor Serv-U for security weaknesses that can be leveraged to disrupt business operations, steal sensitive data, or deploy ransomware. In cases where more severe vulnerabilities enable remote code execution,
attackers may also use the compromised server as an entry point to gain access to an organization's internal network.SolarWinds has advised administrators who are unable to immediately apply the security update to restrict access to the Serv-U server to trusted IP addresses only and, where possible, block malicious or unnecessary HTTP POST requests as a temporary mitigation measure.CISA has since added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that it is being actively exploited in the wild. The agency has also directed all U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate the vulnerability by applying the appropriate security updates no later than June 19, in accordance with the requirements of the Binding Operational Directive (BOD) 22-01.
Affected Products and Versions
Recommendation
The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)
References
Weekly Interesting CVE
| NO. |
CVE Name |
Published Date |
Last Update |
Device/Appplication/OS Target |
Attack Type |
CVSS |
Detail |
Solution |
Reference |
|---|---|---|---|---|---|---|---|---|---|
| 1 |
CVE-2026-10187 |
31/5/2026 |
31/5/2026 |
Totolink N300RH |
Stack-Based Buffer Overflow |
9.3 |
A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. |
No vendor fix or workaround currently provided. |
https://app.opencve.io/cve/CVE-2026-10187
|
| 2 |
CVE-2025-12686 |
27/5/2026 |
27/5/2026 |
Synology |
Buffer Overflow |
9.8 |
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via unspecified vectors |
No vendor fix or workaround currently provided. |
https://www.synology.com/en-global/security/advisory/Synology_SA_25_12
|
| 3 |
CVE-2026-46833 |
28/5/2026 |
29/5/2026 |
Oracle |
Remote Code Execution |
7.5 |
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Net Service. |
Apply the latest security patches. |
|
| 4 |
CVE-2026-42731 |
27/5/2026 |
27/5/2026 |
WordPress miniorange otp verification |
Privilege Escalation |
9.8 |
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation |
Update to version 5.5.0 or later to resolve the vulnerability. |
|
| 5 |
CVE-2026-9955 |
28/5/2026 |
28/5/2026 |
Google Chrome on iOS |
Cross-domain policy |
- |
nappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
Update to version 148.0.7778.216 or later to resolve the vulnerability. |
https://www.cve.org/CVERecord?id=CVE-2026-9955
|
Malware News or Campaign IOC/IOA | EN
|
No |
Campaign Name |
Detection Date |
Attack Type |
Description |
Mitigation/Remediation |
|---|---|---|---|---|---|
| 1 |
New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More |
01/06/2026 |
Phishing, Supply Chain Attack, |
A new vulnerability was discovered in the Linux kernel, which remains exploitable despite partial fixes. The PAN‑OS GlobalProtect (CVE‑2026‑0257) flaw has already been actively exploited; PAN‑OS is the operating system powering Palo Alto Networks firewalls that manage network access and VPNs, meaning such vulnerabilities directly impact enterprise security. A severe Gogs vulnerability allows attackers to execute commands on servers, with no patch available yet. Meanwhile, attackers are increasingly using AI‑generated phishing kits and complex payloads, as well as OAuth phishing that tricks users into granting access without realizing it.Impact: Organizations using PAN‑OS/Prisma Access risk system compromise, Gogs administrators face repository takeover and credential leaks, Linux users must closely follow kernel updates, and all organizations are exposed to phishing campaigns leveraging AI and OAuth. |
|
Ref: https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html
09 June 2026
Viewed 182 time