Skip to content
Data transfer software Serv-U has 15 critical security vulnerabilities

Data transfer software Serv-U has 15 critical security vulnerabilities

Heise.De July 22, 2026

SolarWinds is patching a total of 15 critical security vulnerabilities and one of medium severity with the update to Serv-U 2026.3. The impacts range from privilege escalation and information leaks to the execution of injected malware from the network.

In the Release Notes for Serv-U 2026.3 , SolarWinds lists the individual security vulnerabilities. The software, expanded from an FTP server to a Managed File Transfer system, has received 15 CVE entries for critical vulnerabilities: CVE-2026-28302, CVE-2026-28304 through CVE-2026-28314, and CVE-2026-28316, CVE-2026-28317, and CVE-2026-28321 have a risk rating of “ critical ” with a CVSS score of 9.1 . The vulnerability entry CVE-2026-28315 stands out with a CVSS score of 6.2 and a risk rating of “ medium; ” it is a cross-site scripting vulnerability that can enable session hijacking or unauthorized viewing of an admin account's information.

Interested parties can also find information on new features and improvements that Serv-U 2026.3 brings in the release notes. There, SolarWinds explains, for example, under “General Improvements,” that OpenSSL version 3.0.21 is included, which closes further security vulnerabilities, and that there are general “security improvements.” Bug fixes include, for example, crashes due to HTTP headers with irrelevant “content-encoding: deflate” entries or denial-of-service situations due to anonymous SSH-FTP sessions.

IT managers should not take vulnerabilities in SolarWinds lightly but should promptly apply available software patches. In early June, for example, attackers exploited a denial-of-service vulnerability in Serv-U from the internet . Cybercriminals particularly favor attacking vulnerabilities in such data transfer solutions because they allow access to data that they can then use to extort companies for ransom. This was done en masse by the cyber gang Cl0p in mid-2023 with vulnerabilities in the data transfer software MOVEit from Progress.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.