Junglewise Threat Intelligence

CVE-2026-28304: SolarWinds Serv-U remote code execution via improper access control

CVE-2026-28304 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a critical security vulnerability. An attacker could exploit this flaw to remotely execute arbitrary commands on the server with high privileges (root). This could lead to a complete takeover of the file transfer system, unauthorized access to sensitive customer data, and potential disruption of business operations.

Technical details

SolarWinds Serv-U is vulnerable to remote code execution (RCE) due to improper access control (CWE-284). The vulnerability allows an authenticated attacker with high privileges to execute arbitrary code on the host system. On non-Windows deployments, this execution occurs with root privileges, while the impact is reportedly lower on Windows systems. The attack vector is network-based and does not require user interaction, though it does require high-level administrative credentials. SolarWinds has addressed this issue in Serv-U version 2026.3.

Affected products

  • SolarWinds Serv-U 15.5.4 HF1 and below

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats