TL;DR
SolarWinds fixed 15 critical SolarWinds Serv-U vulnerabilities on July 21, 2026. They allow privilege escalation, account takeover, and remote code execution as root. SolarWinds rates every one of them 9.1 critical.
Why it matters
Serv-U handles managed file transfers for many enterprises. So a compromise can expose sensitive data fast. Managed file transfer tools are prime targets for data theft and extortion. These SolarWinds Serv-U vulnerabilities hit Linux hardest, since each advisory notes lower impact on Windows. Serv-U also has a rough track record. Attackers, including the Clop gang, have abused older Serv-U bugs before. Internet scans have counted over 12,000 exposed Serv-U servers this year. Fifteen critical fixes in one release makes this a priority patch.
How the attacks work
The bugs fall into four groups. Most require existing admin rights, which limits who can abuse them. One notable exception needs only a normal authenticated user.
Insecure direct object reference (IDOR)
Eight flaws stem from insecure direct object references. An IDOR bug lets a user reach objects they should not touch. Several escalate to root command execution. Others hand over accounts outright.
Privilege escalation
Five bugs let an account climb the Serv-U permission ladder. Some push a domain administrator up to system administrator. Others elevate a whole user group at once.
Remote code execution and access control
Two flaws lead to code execution as root directly. Broken access control rounds out the set. One lets a domain admin create rogue system administrator accounts. Another allows arbitrary file read and write.
The full list
| CVE-2026-28302 | IDOR to privilege escalation and RCE as root; needs group admin |
| CVE-2026-28304 | Remote code execution as root |
| CVE-2026-28305 | IDOR to RCE as root; needs domain admin with home directory access |
| CVE-2026-28306 | Domain admin elevates to system administrator |
| CVE-2026-28307 | Domain user group elevated into an administrator group |
| CVE-2026-28308 | IDOR leading to remote code execution; needs domain admin |
| CVE-2026-28309 | Domain admin creates system administrator accounts |
| CVE-2026-28310 | Domain admin escalates user type to system administrator |
| CVE-2026-28311 | Domain admin alters app behaviour, leading to RCE |
| CVE-2026-28312 | Group access elevated to system admin with root code execution |
| CVE-2026-28313 | IDOR to SMTP hijacking and arbitrary account takeover |
| CVE-2026-28314 | IDOR to account takeover; only user authentication required |
| CVE-2026-28316 | IDOR to system admin with root command execution |
| CVE-2026-28317 | IDOR leading to privilege escalation; needs domain admin |
| CVE-2026-28321 | Arbitrary file read and write, then code execution as root |
Affected versions
Every bug affects Serv-U 15.5.4 HF1 and below. The fixed release, Serv-U 2026.3, resolves all 15 at once. Most need existing privileges, so they are not unauthenticated. However, CVE-2026-28314 needs only user authentication for account takeover. That lower bar makes it the standout risk here.
Exploitation status and patch
Researchers reported every bug through the Intigriti bug bounty program. So far, no public exploit or in-the-wild abuse has been confirmed. First, upgrade to Serv-U 2026.3 now. If you cannot upgrade at once, restrict admin and domain access tightly. Also, keep Serv-U off the open internet where possible. Review your Serv-U admin accounts for anything unexpected. With 15 critical SolarWinds Serv-U vulnerabilities now public, prompt patching is the safe move.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.