سيبرانا

قاعدة الثغرات (CVE)

CVE-2026-28318

استهلاك موارد غير محكوم يُسقط SolarWinds Serv-U

عاليةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد

طلبات POST مصمَّمة برأس Content-Encoding: deflate تُسقط خدمة Serv-U دون مصادقة — ثغرة حجب خدمة في خادم نقل الملفات المؤسسي.

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

المنتجات المتأثرة

Productالإصدارات المتأثرةتم الإصلاح في
Serv-U

التغطية على سيبرانا