[NEW] [high] SolarWinds Serv-U: Multiple vulnerabilities
A remote, highly privileged attacker can exploit multiple vulnerabilities in SolarWinds Serv-U to execute arbitrary code as root, gain administrative privileges, take over accounts, disclose confidential information, or perform cross-site scripting attacks.
CSIRTS triage
- What
- Multiple vulnerabilities can allow arbitrary code execution as root, gain administrative privileges, and disclose confidential information.
- Who is affected
- Deployments of SolarWinds Serv-U are affected.
- Urgency
- Remediation is urgent due to high severity and potential for exploitation.
- Action
- Apply the latest security patches provided by SolarWinds.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Serv-U
Get an email when a new Serv-U advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2467
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-283020.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-283040.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-283050.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-283060.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-283070.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-283080.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-283090.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-283100.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-283120.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-28302 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28304 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28305 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28306 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28307 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28308 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28309 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28310 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28311 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28312 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28313 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28314 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28315 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28316 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28317 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-28321 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0265 [1.00] [M/H] Vulnerabilities fixed in SolarWinds Serv-Uncsc-nl
- criticalCVE-2026-28321: SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitr…nvd
- criticalCVE-2026-28317: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that…nvd
- criticalCVE-2026-28316: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that…nvd
- mediumCVE-2026-28315: SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that…nvd
- criticalCVE-2026-28314: SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads …nvd
- criticalCVE-2026-28313: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that…nvd
- criticalCVE-2026-28312: SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a gr…nvd
- criticalCVE-2026-28310: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain adm…nvd
- criticalCVE-2026-28309: SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain ad…nvd
- criticalCVE-2026-28308: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that…nvd
- criticalCVE-2026-28307: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain use…nvd
Recent advisories for SolarWinds Serv-U
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0265 [1.00] [M/H] Vulnerabilities fixed in SolarWinds Serv-Uncsc-nl · 2026-07-27
- criticalCVE-2026-28321: SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitr…nvd · 2026-07-21
- criticalCVE-2026-28317: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that…nvd · 2026-07-21
- criticalCVE-2026-28316: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that…nvd · 2026-07-21
- mediumCVE-2026-28315: SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that…nvd · 2026-07-21
- criticalCVE-2026-28314: SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads …nvd · 2026-07-21
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31