SolarWinds Serv-U

18 known vulnerabilities in SolarWinds Serv-U, 14 critical, 3 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-28318 CVSS 7.5 high · actively exploited SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
  • CVE-2024-28995 CVSS 7.5 high · actively exploited SolarWinds Serv-U Path Traversal Vulnerability
  • CVE-2021-35247 CVSS 5.3 medium · actively exploited SolarWinds Serv-U Improper Input Validation Vulnerability

Latest vulnerabilities

  • CVE-2026-28321 CVSS 9.1 critical SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be…
  • CVE-2026-28317 CVSS 9.1 critical SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This…
  • CVE-2026-28316 CVSS 9.1 critical SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a…
  • CVE-2026-28315 CVSS 6.2 medium SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or…
  • CVE-2026-28314 CVSS 9.1 critical SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication…
  • CVE-2026-28313 CVSS 9.1 critical SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to…
  • CVE-2026-28312 CVSS 9.1 critical SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and…
  • CVE-2026-28310 CVSS 9.1 critical SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to…
  • CVE-2026-28309 CVSS 9.1 critical SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator…
  • CVE-2026-28308 CVSS 9.1 critical SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain…
  • CVE-2026-28307 CVSS 9.1 critical SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator…
  • CVE-2026-28306 CVSS 9.1 critical SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a…
  • CVE-2026-28305 CVSS 9.1 critical SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root…
  • CVE-2026-28304 CVSS 9.1 critical SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code…
  • CVE-2026-28302 CVSS 9.1 critical SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote…
  • CVE-2026-28318 CVSS 7.5 high · actively exploited SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
  • CVE-2024-28995 CVSS 7.5 high · actively exploited SolarWinds Serv-U Path Traversal Vulnerability
  • CVE-2021-35247 CVSS 5.3 medium · actively exploited SolarWinds Serv-U Improper Input Validation Vulnerability