SolarWinds
Serv-U
See the latest tracked release, confirm when it was published, and subscribe for update emails.
2026.3
- Release date
- July 21, 2026
- Security status
- Current version appears affected by 9 high-severity CVEs.
Source
Vendor Release Information
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 2026.3 | 2026-07-21 | Release Notes |
| 15.5.4 | 2026-02-24 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-28321 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations. Affected versions
|
| CVE-2026-28317 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28316 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28314 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28313 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28312 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28310 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28309 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28308 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28307 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28306 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28305 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28304 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments. Affected versions
|
| CVE-2026-28302 | CRITICAL (9.1) | 2026-07-21 | Current versionnot affected | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments. Affected versions
|
| CVE-2025-40541 | CRITICAL (9.1) | 2026-02-24 | Current versionaffected | An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default. Affected versions
|
| CVE-2025-40540 | CRITICAL (9.1) | 2026-02-24 | Current versionaffected | A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default. Affected versions
|
| CVE-2025-40539 | CRITICAL (9.1) | 2026-02-24 | Current versionaffected | A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default. Affected versions
|
| CVE-2025-40538 | CRITICAL (9.1) | 2026-02-24 | Current versionaffected | A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default. Affected versions
|
| CVE-2025-40549 | CRITICAL (9.1) | 2025-11-18 | Current versionaffected | A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences in how paths and home directories are handled. Affected versions
|
| CVE-2025-40548 | CRITICAL (9.1) | 2025-11-18 | Current versionaffected | A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default. Affected versions
|
| CVE-2025-40547 | CRITICAL (9.1) | 2025-11-18 | Current versionaffected | A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default. Affected versions
|
| CVE-2024-45711 | HIGH (7.5) | 2024-10-16 | Current versionaffected | SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when software environment variables are abused. Authentication is required for this vulnerability Affected versions
|
| CVE-2023-40060 | HIGH (7.2) | 2023-09-07 | Current versionaffected | A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4. SolarWinds found that the issue was not completely fixed in 15.4 Hotfix 1. Affected versions
|