SolarWinds disclosed CVE-2024-28995, a high-severity directory traversal and local file disclosure flaw in its Serv-U managed file transfer software that affects versions earlier than 15.4.2 Hotfix 2. The vulnerability can be exploited remotely and without authentication via crafted HTTP GET requests, allowing attackers to read arbitrary files from the host system, including sensitive material such as credentials, certificates, and configuration data. Rapid7 described the issue as trivially exploitable, and SolarWinds issued fixes through Serv-U 15.4.2 HF2, with deployment requiring 15.4.2 HF1 first.
Security researchers and national defenders reported that exploitation began quickly after disclosure. GreyNoise observed internet-wide exploitation activity targeting exposed Serv-U instances, while CSIRT.SK warned that public scanning tools and proof-of-concept exploit code were increasing the likelihood of opportunistic attacks. The combination of unauthenticated access, straightforward exploitation, and the ability to extract sensitive files has made patching exposed Serv-U servers an urgent priority.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK issued an alert that CVE-2024-28995 was being actively exploited and noted that public scanning tools and proof-of-concept exploit code increased the risk of opportunistic attacks. The advisory urged immediate upgrading to Serv-U 15.4.2 HF2.
GreyNoise reported seeing exploitation activity for CVE-2024-28995 against SolarWinds Serv-U in the wild, indicating attackers were actively targeting the vulnerability after disclosure.
Rapid7 published technical analysis describing CVE-2024-28995 in SolarWinds Serv-U as a trivially exploitable information disclosure flaw, highlighting the ease with which unauthenticated attackers could read arbitrary files.
SolarWinds published a security advisory and release notes for Serv-U 15.4.2 Hotfix 2 to address CVE-2024-28995, a directory traversal/local file disclosure vulnerability affecting versions earlier than 15.4.2 HF2.
5 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcelabs.greynoise.io
Open sourcerapid7.com
Open sourcesolarwinds.com
Open sourcesupport.solarwinds.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.