CVE-2026-28306
SolarWinds Serv‑U has a critical privilege‑escalation flaw. A domain administrator can use it to gain full system administrator rights, giving them complete control over the affected machine. The flaw is especially dangerous on Windows systems.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
SolarWinds Serv‑U (all versions) – any installation that allows domain administrators to log in.
Real-world impact
An attacker who is already a domain administrator could use this flaw to become a system administrator, giving them unrestricted access to files, services, and the ability to install software or change system settings.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability is easy to exploit over the network, requires only a domain‑administrator account, and gives the attacker full control over confidentiality, integrity, and availability of the system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- documentation.solarwinds.com/en/success_center/servu/con…release notesvendor advisory
- solarwinds.com/trust-center/security-advis…vendor advisory