SolarWinds Serv-U Update Addresses 15 Critical Vulnerabilities

SolarWinds Serv-U Update Addresses 15 Critical Vulnerabilities

First seen 22 Jul 2026, 12:54 UTC GbhackersHeise.Dewww.solarwinds.com 78% similarity 72.8

Article Content

Browse articles
ThreatCluster

SolarWinds has released an update for Serv-U 2026.3, patching 15 critical vulnerabilities with CVSS scores of 9.1, allowing for remote code execution and privilege escalation. The vulnerabilities, identified as CVE-2026-28302, CVE-2026-28304 through CVE-2026-28314, CVE-2026-28316, CVE-2026-28317, and CVE-2026-28321, pose significant risks to managed file transfer and FTP server platforms. Affected systems include Unix-like and Windows environments. Attackers can exploit these vulnerabilities to execute injected malware or escalate privileges, leading to potential data breaches. IT managers are advised to apply the patches immediately to mitigate risks, especially following recent exploitation of a denial-of-service vulnerability in early June. The update also includes general security improvements and bug fixes.

Key Points: • SolarWinds patched 15 critical vulnerabilities in Serv-U with CVSS scores of 9.1. • Vulnerabilities allow for remote code execution and privilege escalation on affected systems. • IT managers are urged to apply patches promptly to prevent exploitation.

ThreatCluster AI

Timeline

2026-07-21
CVE-2026-28302 published
CVE-2026-28302 identified as a critical vulnerability with a CVSS score of 9.1.
Heise.De
2026-07-21
CVE-2026-28304 published
CVE-2026-28304 through CVE-2026-28314 published, all rated critical with CVSS scores of 9.1.
Heise.De
2026-07-21
CVE-2026-28315 published
CVE-2026-28315 identified as a medium severity cross-site scripting vulnerability.
Heise.De
2026-07-21
CVE-2026-28316 published
CVE-2026-28316 published as part of the critical vulnerabilities affecting Serv-U.
Heise.De
2026-07-21
CVE-2026-28317 published
CVE-2026-28317 published, contributing to the critical vulnerabilities in Serv-U.
Heise.De
2026-07-21
CVE-2026-28321 published
CVE-2026-28321 published as a critical vulnerability in the Serv-U software.
Heise.De
2026-07-21
CVE-2026-28314 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
Serv-U 2026.3 released
SolarWinds released Serv-U 2026.3, addressing 15 critical vulnerabilities and enhancing security.
Gbhackers

Community

Browse all →