CVE-2026-28307
CVE-2026-28307 is a critical privilege escalation vulnerability in SolarWinds Serv-U (CWE-284) allowing domain user groups to gain administrator-level access. The attack requires high privileges and network access, with higher impact on non-Windows systems. CVSS score: 9.1.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
SolarWinds Serv-U users
Real-world impact
Attackers could escalate privileges to administrator level, potentially gaining full control of the system.
Why this severity
Critical severity due to high exploitability and potential for full system compromise.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No official fix documented in provided sources (CISA KEV or vendor advisory).
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- documentation.solarwinds.com/en/success_center/servu/con…release notesvendor advisory
- solarwinds.com/trust-center/security-advis…vendor advisory