Improper handling of exceptional conditions in Serv-U FTP Server - CVE-2026-28318
Published: June 9, 2026
Serv-U FTP Server
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of deflate-encoded post requests in Serv-U service when handling HTTP POST requests with Content-Encoding: deflate. A remote attacker can send a specially crafted HTTP POST request to cause a denial of service.
Note, the vulnerability is being exploited in the wild.