Skip to content
SolarWindsCVE-2026-28304

SolarWinds Serv-U: remote code execution

Critical9.1CVE-2026-28304 · Published Jul 21, 2026 · updated Jul 24, 2026

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.

SolarWinds advisory

Affected versions

PackageAffectedFixed in
Serv-U
Product
<= 15.5.4 HF1 and belowNo fix yet
Details and references

More SolarWinds advisories

All SolarWinds
Advisory
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: improper access control
Critical9.1Jul 21
SolarWinds Serv-U: privilege escalation
Critical9.1Jul 21
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: cross-site scripting
Medium6.2Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.