SolarWinds disclosed and patched multiple high-severity vulnerabilities in Serv-U that can let authenticated attackers take over accounts, escalate privileges, read and write arbitrary files, and in some cases achieve remote code execution as root. The issues affect Serv-U 15.5.4 HF1 and earlier on both Windows and Linux, with SolarWinds noting the impact is generally more severe on Linux and lower on Windows. The vendor fixed the flaws in Serv-U 2026.3 and said the vulnerabilities were reported through the Intigriti bug bounty program.
The disclosed CVEs include broken access control, privilege escalation, and IDOR weaknesses such as CVE-2026-28321 for arbitrary file read/write that can be leveraged into code execution, CVE-2026-28312 and CVE-2026-28310 for elevation to system administrator, CVE-2026-28309 for creating system administrator accounts, and CVE-2026-28313, CVE-2026-28314, CVE-2026-28316, and CVE-2026-28317 for account takeover, SMTP hijacking, and further privilege escalation. SolarWinds said the bugs require existing privileges rather than unauthenticated access, but warned that stolen or low-tier credentials could be chained to gain full control of a Serv-U host; no public exploits or confirmed in-the-wild abuse had been reported at disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
SolarWinds PSIRT received at least some of the newly disclosed Serv-U vulnerability reports on 2026-07-21, including CVE-2026-28309 and CVE-2026-28316. These reports covered privilege escalation and access control issues affecting Serv-U 15.5.4 HF1 and earlier.
On 2026-07-21, SolarWinds disclosed and remediated multiple high-severity Serv-U vulnerabilities affecting version 15.5.4 HF1 and earlier, releasing fixes in Serv-U 2026.3. The issues included privilege escalation, broken access control, and IDOR flaws, with Linux systems facing the highest impact and no public exploitation reported at disclosure time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecyber.gc.ca
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcesolarwinds.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.