Critical Vulnerabilities in SolarWinds Serv-U Require Immediate Patching

Critical Vulnerabilities in SolarWinds Serv-U Require Immediate Patching

First seen 22 Jul 2026, 12:54 UTC GbhackersHeise.Dewww.solarwinds.comCsa.Sg 83% similarity 72.9

Article Content

Browse articles
ThreatCluster

SolarWinds has identified 15 critical vulnerabilities in its Serv-U software, including two that allow remote code execution (RCE). The vulnerabilities, with CVSS scores of 9.1, affect versions 15.5.4 HF1 and below, as well as Serv-U 2026.3. Attackers can exploit these vulnerabilities to execute arbitrary code and escalate privileges. The vulnerabilities were published on 2026-07-21, and users are urged to apply patches immediately to mitigate risks. The Serv-U software is widely used for managed file transfers, making it a significant target for cybercriminals. Previous incidents, such as the MOVEit attacks, highlight the dangers of unpatched vulnerabilities in data transfer solutions. Administrators are advised to review the release notes for detailed information on the vulnerabilities and the necessary updates.

Key Points: • SolarWinds Serv-U has 15 critical vulnerabilities, including two allowing remote code execution. • Patches are available for affected versions, and immediate application is recommended. • The vulnerabilities could lead to significant data breaches and exploitation by cybercriminals.

ThreatCluster AI

Timeline

2026-07-21
Multiple CVEs published for Serv-U vulnerabilities
SolarWinds disclosed 15 critical vulnerabilities in Serv-U, including CVE-2026-28304 and CVE-2026-28311, with CVSS scores of 9.1.
Heise.De
2026-07-21
CVE-2026-28316 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-28302 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-28321 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-28317 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-28314 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-28304 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-28315 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
Serv-U 2026.3 released with security patches
SolarWinds released an update for Serv-U to address the 15 critical vulnerabilities, urging immediate patching.
Gbhackers
2026-07-23
Security advisory issued for critical vulnerabilities
The Cyber Security Agency of Singapore issued an advisory on two critical vulnerabilities in Serv-U, urging immediate updates.
Csa.Sg

Community

Browse all →