Improper handling of exceptional conditions in Serv-U FTP Server - CVE-2026-28318
Published: June 9, 2026 / Updated: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of deflate-encoded post requests in Serv-U service when handling HTTP POST requests with Content-Encoding: deflate. A remote attacker can send a specially crafted HTTP POST request to cause a denial of service.
Note, the vulnerability is being exploited in the wild.