Solarwinds Serv-U vulnerabilities
55 known vulnerabilities affecting solarwinds/serv-u.
Total CVEs
55
CISA KEV
4
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL19HIGH20MEDIUM16
Vulnerabilities
Page 2 of 3
CVE-2026-28317P3CRITICALCVSS 9.1fixed in 2026.3v15.5.4 HF1 and below2026-07-21
CVE-2026-28317 [CRITICAL] CWE-639 CVE-2026-28317: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can l
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
nvd
CVE-2025-40538P3HIGHCVSS 7.2fixed in 15.5.4vSolarWinds Serv-U 15.5.3 and prior versions2026-02-24
CVE-2025-40538 [HIGH] CWE-269 CVE-2025-40538: A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor
A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium bec
nvd
CVE-2026-28310P3CRITICALCVSS 9.1fixed in 2026.3v15.5.4 HF1 and below2026-07-21
CVE-2026-28310 [CRITICAL] CWE-862 CVE-2026-28310: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administr
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
nvd
CVE-2026-28306P3CRITICALCVSS 9.1fixed in 2026.3v15.5.4 HF1 and below2026-07-21
CVE-2026-28306 [CRITICAL] CWE-284 CVE-2026-28306: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administr
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
nvd
CVE-2026-28307P3CRITICALCVSS 9.1fixed in 2026.3v15.5.4 HF1 and below2026-07-21
CVE-2026-28307 [CRITICAL] CWE-284 CVE-2026-28307: SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user grou
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
nvd
CVE-2026-28313P3CRITICALCVSS 9.1fixed in 2026.3v15.5.4 HF1 and below2026-07-21
CVE-2026-28313 [CRITICAL] CWE-639 CVE-2026-28313: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can l
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
nvd
CVE-2025-40539P3HIGHCVSS 7.2fixed in 15.5.4vSolarWinds Serv-U 15.5.3 and prior versions2026-02-24
CVE-2025-40539 [HIGH] CWE-704 CVE-2025-40539: A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ab
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by defau
nvd
CVE-2025-40540P3HIGHCVSS 7.2fixed in 15.5.4vSolarWinds Serv-U 15.5.3 and prior versions2026-02-24
CVE-2025-40540 [HIGH] CWE-704 CVE-2025-40540: A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ab
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by defau
nvd
CVE-2025-40541P3HIGHCVSS 7.2fixed in 15.5.4vSolarWinds Serv-U 15.5.3 and prior versions2026-02-24
CVE-2025-40541 [HIGH] CWE-704 CVE-2025-40541: An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, giv
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged servic
nvd
CVE-2023-35179P3HIGHCVSS 7.2v15.4.0v15.4 2023-08-11
CVE-2023-35179 [HIGH] CWE-284 CVE-2023-35179: A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypas
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action.
nvd
CVE-2023-40060P3HIGHCVSS 7.2v15.4.0≥ 15.4, ≤ 15.4 Hotfix 1 2023-09-07
CVE-2023-40060 [HIGH] CWE-284 CVE-2023-40060: A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action.
15.4. SolarWinds found that the issue was not completely fixed in 15.4 Hotfix 1.
nvd
CVE-2021-35242P3HIGHCVSS 8.8fixed in 15.2.52021-12-06
CVE-2021-35242 [HIGH] CWE-352 CVE-2021-35242: Serv-U server responds with valid CSRFToken when the request contains only Session.
Serv-U server responds with valid CSRFToken when the request contains only Session.
nvd
CVE-2021-3154P3HIGHCVSS 7.5fixed in 15.2.22021-05-04
CVE-2021-3154 [HIGH] CVE-2021-3154: An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve c
An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.
nvd
CVE-2024-28073P3HIGHCVSS 7.2fixed in 15.4.22024-04-17
CVE-2024-28073 [HIGH] CWE-22 CVE-2024-28073: SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. Th
SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.
nvd
CVE-2020-27994P3MEDIUMCVSS 6.5fixed in 15.2.22021-02-03
CVE-2020-27994 [MEDIUM] CWE-22 CVE-2020-27994: SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
nvd
CVE-2023-23841P3HIGHCVSS 7.5fixed in 15.42023-06-15
CVE-2023-23841 [HIGH] CWE-319 CVE-2023-23841: SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Sh
SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request. Part of the URL of the request discloses sensitive data.
nvd
CVE-2021-35252P3HIGHCVSS 7.5fixed in 15.3.22022-12-16
CVE-2021-35252 [HIGH] CWE-798 CVE-2021-35252: Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
nvd
CVE-2020-15576P3HIGHCVSS 7.5fixed in 15.2.12020-07-07
CVE-2020-15576 [HIGH] CVE-2020-15576: SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.
SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.
nvd
CVE-2020-15574P3HIGHCVSS 7.5fixed in 15.2.12020-07-07
CVE-2020-15574 [HIGH] CVE-2020-15574: SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Numb
SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.
nvd
CVE-2021-25276P3HIGHCVSS 7.1fixed in 15.2.2v15.2.22021-02-03
CVE-2021-25276 [HIGH] CWE-732 CVE-2021-25276: In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (tha
In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add an FTP user by copying a valid profile file to this directory. For example, if this profile sets up a
nvd