Last updated: July 23, 2026
SolarWinds Serv-U: Multiple Critical Vulnerabilities (CVE-2026-28302, CVE-2026-16232)
This text was generated using artificial intelligence (AI).Update July 23, 2026: In addition, three other critical vulnerabilities (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145) with a CVSS score of 9.3 have been identified and are being actively exploited. See below for details.
According to the SolarWinds Security Advisory dated July 21, 2026 The vendor has announced a bundle of 15 critical security vulnerabilities in its Managed File Transfer (MFT) software, Serv-U. According to the manufacturer, the vulnerabilities—led by CVE-2026-28302—affect all versions up to and including 15.5.4 HF1. The manufacturer assesses the risk with a CVSS score of 9.1, which indicates a high risk to affected systems. An update to address the vulnerabilities is available.
The Facts at a Glance
- CVE-2026-28302 and 14 other vulnerabilities: CVSS 9.1; affects all versions up to 15.5.4 HF1; patch available in version 2026.3
- CVE-2026-16232, CVE-2026-62144, CVE-2026-62145: CVSS 9.3, affecting Security Management Server and Multi-Domain Security Management Server (R77.30 through R82.10), Patches available (R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+), actively exploited
Technical Overview of the Vulnerabilities
CVE-2026-28302 and Related Vulnerabilities
According to the SolarWinds advisory, 15 vulnerabilities were documented for this vulnerability complex, under a total of 16 CVE identifiers. The primary identifier is CVE-2026-28302, accompanied by the following additional CVEs: CVE-2026-28304 through CVE-2026-28317, as well as CVE-2026-28321. According to the vendor’s assessment, the high number of identifiers indicates deep-seated security issues in the software.
Affected versions: all releases up to and including 15.5.4 HF1 and below.
The CVSS vector specified by the manufacturer CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H describes a network-based attack that, while requiring high privileges, is relatively simple. The „Scope Changed“ (S:C) attribute is particularly critical: it means that a successful attack can extend beyond the application’s boundaries and compromise the underlying operating system. Since both the CVSS vector and score are based exclusively on vendor information at the time of publication and independent verification via the NVD is still pending, administrators should check the details directly in the SolarWinds Trust Center Check.
CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145: Authentication bypass in Check Point SmartConsole
According to Check Point Security Advisory SK185169 These three vulnerabilities allow an authentication bypass in the SmartConsole component of Check Point Security Management Server and Multi-Domain Security Management Server. The CVSS score CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N describes a network-based attack that does not require privileges or user interaction. With a score of 9.3 These vulnerabilities pose a critical risk.
Affected versions include Security Management Server and Multi-Domain Security Management Server in releases R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10. Check Point has released patches for the current versions: R82.10 Take 36 and later, R82 Take 118 and later, and R81.20 Take 158 and later.
Particularly critical: According to Check Point, these vulnerabilities actively utilized. Attackers can gain full administrative access to the management console without authentication, which allows them to completely compromise the managed security infrastructure. This includes access to configuration data, firewall rules, and potentially sensitive network information.
Risk Assessment for Businesses
SolarWinds Serv-U is used in many organizations for the automated and secure exchange of business-critical data. MFT systems are often deeply integrated into core processes, such as data exchange with suppliers, transaction processing, or software distribution. A compromise can therefore have serious consequences, including:
- Data Theft: Unauthorized access to sensitive information exchanged via the server.
- Business Interruptions: Manipulation or deletion of data necessary for business operations.
- Lateral spread: Using the compromised server as a foothold to attack partner companies via file transfer channels (third-party breach scenario).
Although the attack vector for CVE-2026-28302 requires high privileges, this poses a realistic risk in scenarios involving stolen administrator credentials or insider threats. The „Scope Change“ capability allows attackers to install ransomware, exfiltrate data, or misuse the server as a foothold for further attacks on the network.
The newly disclosed Check Point vulnerabilities (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145) significantly exacerbate the threat landscape, as they do not require elevated privileges and are already being actively exploited. Organizations using Check Point Security Management Server are at immediate risk.
SolarWinds Serv-U has repeatedly been the target of critical security vulnerabilities over the past 24 months: In February 2026, four critical RCE vulnerabilities (CVE-2025-40538 through CVE-2025-40541, CVSS 9.1) were patched in Serv-U 15.5.4; in June 2026, CISA added an actively exploited denial-of-service bug (CVE-2026-28318) to its Known Exploited Vulnerabilities catalog. This cluster of incidents underscores that Serv-U remains a persistent target for attacks and that continuous vendor risk monitoring for SolarWinds products is essential. (Sources: BleepingComputer, February 2026; TheHackerNews, June 2026)
Additional reporting requirements apply to organizations in the DACH region: In the event of a confirmed security incident involving access to personal data, the GDPR reporting requirement under Article 33 applies (72-hour deadline for reporting to the competent supervisory authority). Operators of essential services as defined by the NIS 2 Directive—such as those in the healthcare sector, the financial sector, or public administration—are also required to report significant security incidents without delay. The BSI generally recommends immediately updating exposed MFT systems and management consoles in the event of critical vulnerabilities of this severity.
Recommended countermeasures
For SolarWinds Serv-U (CVE-2026-28302 and related vulnerabilities)
The only measure recommended by the manufacturer is to install the provided update immediately. According to the SolarWinds advisory, the version 2026.3 has been released, which is intended to address all of the vulnerabilities described. According to the latest information from the manufacturer, there are no known alternative protective measures or temporary workarounds, which is why this update should be treated as a top priority.
Administrators should note that the version number „2026.3” differs from the previous Serv-U versioning scheme (e.g., 15.x.x). Please keep this in mind when searching for the correct patch in the Customer Portal or on the SolarWinds product page.
For Check Point Security Management Server (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145)
Due to active exploitation, it is imperative that you install the available patches immediately:
- R82.10: Update to Take 36 or later
- R82: Update to Take 118 or higher
- R81.20: Update to Take 158 or later
For older versions (R77.30 through R81.10), organizations should review the migration path to a supported version or consider temporary network segmentation to reduce the attack surface. Check Point also recommends reviewing audit logs for suspicious authentication attempts or unusual administrative activity.
Gain visibility into your own attack surface with LocateRisk
Security incidents like this underscore the need to continuously monitor one’s own external attack surface. Companies often lack a complete overview of which software versions are in use on their publicly accessible systems—especially when it comes to shadow IT, forgotten subdomains, or uncataloged cloud assets that are not included in the internal asset inventory.
LocateRisk helps organizations achieve this transparency:
- External Attack Surface Management (EASM): The platform continuously identifies all externally accessible assets and can detect deployed software—such as SolarWinds Serv-U or Check Point Security Management Server—through service fingerprinting. Version information is compared against up-to-date vulnerability databases, allowing potentially vulnerable systems within the externally visible infrastructure to be identified—serving as the basis for prioritized patch management.
- Continuous Vendor Risk Management (C-VRM): The solution continuously assesses the security status of suppliers and service providers. In light of the repeated Serv-U incidents in recent months, C-VRM can alert companies when a critical vendor such as SolarWinds or Check Point is affected by a serious vulnerability—enabling them to proactively respond to changes in the supply chain’s risk profile.
By combining these approaches, risks posed by CVE-2026-28302 and the Check Point vulnerabilities can be identified, assessed, and prioritized more quickly.
Sources and further information
Frequently asked questions
According to the SolarWinds advisory, all versions up to and including 15.5.4 HF1 are affected. Organizations running these or older versions should update to the patched version immediately.
According to the manufacturer, SolarWinds has released version 2026.3 has been released, which is intended to address all 15 vulnerabilities in the software suite. Since the version number differs from the previous scheme (15.x.x), administrators should download the patch directly from the SolarWinds Customer Portal or the Trust Center refer to.
As of the date of the advisory's publication on July 21, 2026, according to the vendor, there were no confirmed reports of active exploitation of these specific vulnerabilities. Administrators should monitor the SolarWinds Trust Center and relevant threat intelligence sources for updates.
Yes. According to the Check Point Security Advisory, these vulnerabilities are being actively exploited. Organizations using affected versions of the Security Management Server should install the available patches as a top priority and check their systems for signs of compromise.
This affects Security Management Servers and Multi-Domain Security Management Servers in versions R77.30 through R82.10. Patches are available for R82.10 (Take 36+), R82 (Take 118+), and R81.20 (Take 158+). For older versions, you should consider migrating to a supported version.
As of July 23, 2026. This post is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.