Skip to content
SolarWindsCVE-2026-28315

SolarWinds Serv-U: cross-site scripting

Medium6.2CVE-2026-28315 · Published Jul 21, 2026 · updated Jul 24, 2026

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.

SolarWinds advisory

Affected versions

PackageAffectedFixed in
Serv-U
Product
<= 15.5.4 HF1 and belowNo fix yet
Details and references

More SolarWinds advisories

All SolarWinds
Advisory
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: improper access control
Critical9.1Jul 21
SolarWinds Serv-U: privilege escalation
Critical9.1Jul 21
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.