SolarWinds Serv-U: 15 Critical Vulnerabilities (CVE-2026-28302) Require an Immediate Update
This text was generated using artificial intelligence (AI).According to the SolarWinds Security Advisory dated July 21, 2026 The vendor has announced a bundle of 15 critical security vulnerabilities in its Managed File Transfer (MFT) software, Serv-U. According to the manufacturer, the vulnerabilities—led by CVE-2026-28302—affect all versions up to and including 15.5.4 HF1. The manufacturer assesses the risk with a CVSS score of 9.1, which indicates a high risk to affected systems. An update to address the vulnerabilities is available.
Technical Overview of the Vulnerabilities
According to the SolarWinds advisory, 15 vulnerabilities were documented for this vulnerability complex, under a total of 16 CVE identifiers. The primary identifier is CVE-2026-28302, accompanied by the following additional CVEs: CVE-2026-28304 through CVE-2026-28317, as well as CVE-2026-28321. According to the vendor’s assessment, the high number of identifiers indicates deep-seated security issues in the software.
Affected versions: all releases up to and including 15.5.4 HF1 and below.
The CVSS vector specified by the manufacturer CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H describes a network-based attack that, while requiring high privileges, is relatively simple. The „Scope Changed“ (S:C) attribute is particularly critical: it means that a successful attack can extend beyond the application’s boundaries and compromise the underlying operating system. Since both the CVSS vector and score are based exclusively on vendor information at the time of publication and independent verification via the NVD is still pending, administrators should check the details directly in the SolarWinds Trust Center Check.
Risk Assessment for Businesses
SolarWinds Serv-U is used in many organizations for the automated and secure exchange of business-critical data. MFT systems are often deeply integrated into core processes, such as data exchange with suppliers, transaction processing, or software distribution. A compromise can therefore have serious consequences, including:
- Data Theft: Unauthorized access to sensitive information exchanged via the server.
- Business Interruptions: Manipulation or deletion of data necessary for business operations.
- Lateral spread: Using the compromised server as a foothold to attack partner companies via file transfer channels (third-party breach scenario).
Although this attack vector requires high privileges, it poses a realistic risk in scenarios involving stolen administrator credentials or insider threats. The „Scope Change“ capability allows attackers to install ransomware, exfiltrate data, or misuse the server as a foothold for further attacks on the network.
SolarWinds Serv-U has repeatedly been the target of critical security vulnerabilities over the past 24 months: In February 2026, four critical RCE vulnerabilities (CVE-2025-40538 through CVE-2025-40541, CVSS 9.1) were patched in Serv-U 15.5.4; in June 2026, CISA added an actively exploited denial-of-service bug (CVE-2026-28318) to its Known Exploited Vulnerabilities catalog. This cluster of incidents underscores that Serv-U remains a persistent target for attacks and that continuous vendor risk monitoring for SolarWinds products is essential. (Sources: BleepingComputer, February 2026; TheHackerNews, June 2026)
Additional reporting requirements apply to organizations in the DACH region: In the event of a confirmed security incident involving access to personal data, the GDPR reporting requirement under Article 33 applies (72-hour deadline for reporting to the competent supervisory authority). Operators of essential services as defined by the NIS 2 Directive—such as those in the healthcare sector, the financial sector, or public administration—are also required to report significant security incidents without delay. The BSI generally recommends immediately updating exposed MFT systems in the event of critical vulnerabilities of this severity.
Recommended countermeasures
The only measure recommended by the manufacturer is to install the provided update immediately. According to the SolarWinds advisory, the version 2026.3 has been released, which is intended to address all of the vulnerabilities described. According to the latest information from the manufacturer, there are no known alternative protective measures or temporary workarounds, which is why this update should be treated as a top priority.
Administrators should note that the version number „2026.3” differs from the previous Serv-U versioning scheme (e.g., 15.x.x). Please keep this in mind when searching for the correct patch in the Customer Portal or on the SolarWinds product page.
Gain visibility into your own attack surface with LocateRisk
Security incidents like this underscore the need to continuously monitor one’s own external attack surface. Companies often lack a complete overview of which software versions are in use on their publicly accessible systems—especially when it comes to shadow IT, forgotten subdomains, or uncataloged cloud assets that are not included in the internal asset inventory.
LocateRisk helps organizations achieve this transparency:
- External Attack Surface Management (EASM): The platform continuously identifies all externally accessible assets and can detect deployed software, such as SolarWinds Serv-U, through service fingerprinting. Version information is compared against current vulnerability databases, allowing potentially vulnerable systems within the externally visible infrastructure to be identified—serving as the basis for prioritized patch management.
- Continuous Vendor Risk Management (C-VRM): The solution continuously assesses the security status of suppliers and service providers. In light of the repeated Serv-U incidents in recent months, C-VRM can alert companies when a critical vendor such as SolarWinds is affected by a serious vulnerability—enabling them to proactively respond to changes in the supply chain’s risk profile.
By combining these approaches, risks posed by CVE-2026-28302 can be identified, assessed, and prioritized more quickly.
Frequently Asked Questions
Which versions of SolarWinds Serv-U are affected by CVE-2026-28302?
According to the SolarWinds advisory, all versions up to and including 15.5.4 HF1 are affected. Organizations running these or older versions should update to the patched version immediately.
Which update addresses the security vulnerabilities described?
According to the manufacturer, SolarWinds has released version 2026.3 has been released, which is intended to address all 15 vulnerabilities in the software suite. Since the version number differs from the previous scheme (15.x.x), administrators should download the patch directly from the SolarWinds Customer Portal or the Trust Center refer to.
Is CVE-2026-28302 being actively exploited?
As of the date of the advisory's publication on July 21, 2026, according to the vendor, there were no confirmed reports of active exploitation of these specific vulnerabilities. Administrators should monitor the SolarWinds Trust Center and relevant threat intelligence sources for updates.
Sources and further information