SolarWinds has patched CVE-2026-28318, a denial-of-service vulnerability in Serv-U that has been exploited in the wild.

CISA warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers.

CISA added CVE-2026-28318, a high-severity SolarWinds Serv-U DoS flaw, to its KEV catalog after evidence of active exploitation.