Published 6/4/2026 · updated 6/5/2026 · CWE-400
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Percentile p90 — Higher than 90% of all CVEs — elevated exploitation risk.
Which upstream feeds returned data for this CVE, and when they were last fetched.
Added 2026-06-05 · Remediation overdue by 45 days.
Unlock the full report
Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.