Back to search

SolarWinds

Serv-U

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: 2026-07-21

2026.3

Release date
July 21, 2026
Security status
15 high-severity CVEs tracked in the last 90 days. Current version not affected.

Source

Vendor Release Information

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
2026.3 2026-07-21 Release Notes
15.5.4 2026-02-24 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-28321 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28317 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28316 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28314 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28313 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28312 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28310 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28309 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28308 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28307 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28306 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28305 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28304 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28302 CRITICAL (9.1) 2026-07-21 Current versionnot affected

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.

Affected versions
  • 15.5.4 HF1 and below
CVE-2026-28318 HIGH (7.5) 2026-06-04 Current versionnot affected

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

Affected versions
  • Up to (excluding) 15.5.4