Attackers can exploit two critical vulnerabilities in SolarWinds Serv-U to perform remote code execution. Patch immediately.
SolarWinds has released security updates to address two vulnerabilities (CVE-2026-28304 and CVE-2026-28311) affecting SolarWinds Serv-U. SolarWinds Serv-U is a multi-protocol file server capable of sending and receiving files from other networked computers.
These vulnerabilities have a Common Vulnerability Scoring System (CVSS v3.1) score of 9.1 out of 10.
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-28304: A remote code execution vulnerability that can allow an attacker to execute arbitrary code as root.
CVE-2026-28311: A remote code execution vulnerability that can allow a domain administrator to modify how the application behaves and perform remote code execution.
These vulnerabilities affect SolarWinds Serv-U versions 15.5.4 HF1 and below.
Users and administrators of affected products are advised to update to the latest versions immediately.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
