CVE-2026-28302
SolarWinds Serv‑U has a critical flaw that lets attackers with group admin rights access files and run code as the system. The vulnerability is an insecure direct object reference that can be abused to gain root privileges. It is especially dangerous on Windows but also affects other deployments.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
SolarWinds Serv‑U servers, any version that has not been patched, typically used by organizations running web and file services.
Real-world impact
An attacker who can reach a Serv‑U server could read or modify any file, execute arbitrary code, and take full control of the system.
Why this severity
The CVSS score of 9.1 reflects that the flaw is network‑based, requires low effort, and gives an attacker high privileges with no user interaction. The vector shows that an attacker can exploit it remotely, with low complexity, high privileges, and can compromise confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- documentation.solarwinds.com/en/success_center/servu/con…release notes
- solarwinds.com/trust-center/security-advis…vendor advisory