Heise.De
SolarWinds Serv-U Update Addresses 15 Critical Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
SolarWinds has released an update for Serv-U 2026.3, patching 15 critical vulnerabilities with CVSS scores of 9.1, allowing for remote code execution and privilege escalation. The vulnerabilities, identified as CVE-2026-28302, CVE-2026-28304 through CVE-2026-28314, CVE-2026-28316, CVE-2026-28317, and CVE-2026-28321, pose significant risks to managed file transfer and FTP server platforms. Affected systems include Unix-like and Windows environments. Attackers can exploit these vulnerabilities to execute injected malware or escalate privileges, leading to potential data breaches. IT managers are advised to apply the patches immediately to mitigate risks, especially following recent exploitation of a denial-of-service vulnerability in early June. The update also includes general security improvements and bug fixes.
Key Points: • SolarWinds patched 15 critical vulnerabilities in Serv-U with CVSS scores of 9.1. • Vulnerabilities allow for remote code execution and privilege escalation on affected systems. • IT managers are urged to apply patches promptly to prevent exploitation.