SolarWinds Serv-U: Multiple Critical Vulnerabilities (CVE-2026-28302, CVE-2026-16232)


This text was generated using artificial intelligence (AI).Update July 23, 2026: In addition, three other critical vulnerabilities (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145) with a CVSS score of 9.3 have been identified and are being actively exploited. See below for details.

According to the SolarWinds Security Advisory dated July 21, 2026 The vendor has announced a bundle of 15 critical security vulnerabilities in its Managed File Transfer (MFT) software, Serv-U. According to the manufacturer, the vulnerabilities—led by CVE-2026-28302—affect all versions up to and including 15.5.4 HF1. The manufacturer assesses the risk with a CVSS score of 9.1, which indicates a high risk to affected systems. An update to address the vulnerabilities is available.