{"id":9189,"date":"2026-07-22T09:33:45","date_gmt":"2026-07-22T09:33:45","guid":{"rendered":"https:\/\/locaterisk.com\/de\/?p=9189"},"modified":"2026-07-23T08:44:25","modified_gmt":"2026-07-23T08:44:25","slug":"solarwinds-servu-15-critical-security-vulnerabilities-cve-2026-28302","status":"publish","type":"post","link":"https:\/\/locaterisk.com\/en\/solarwinds-servu-15-critical-security-vulnerabilities-cve-2026-28302\/","title":{"rendered":"SolarWinds Serv-U: Multiple Critical Vulnerabilities (CVE-2026-28302, CVE-2026-16232)"},"content":{"rendered":"<div class=\"wp-block-lr-blog-article-header-module\">\n    <div class=\"content\">\n\t\t<div class=\"headline\">\n\t\t\t<a class=\"to-blog-button\" href=\"https:\/\/locaterisk.com\/en\/blog\/\">\n\t\t\t\t<span class=\"to-blog-arrow\" aria-hidden=\"true\">\u2190<\/span>\n\t\t\t\t<span>Back to Blog<\/span>\n\t\t\t<\/a>\n\t\t\t<div class=\"article-meta\">\n\t\t\t\t\t\t\t\t\t<p class=\"post-updated\">Last updated: July 23, 2026<\/p>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n        <div class=\"main-content\">\n\t\t\t<h1 class=\"title\">SolarWinds Serv-U: Multiple Critical Vulnerabilities (CVE-2026-28302, CVE-2026-16232)<\/h1>\n\t\t\t\t\t\t\t<p class=\"paragraph\"><span class=\"lr-ai-disclosure\" style=\"margin:8px 0 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic\">This text was generated using artificial intelligence (AI).<\/span><strong>Update July 23, 2026:<\/strong> In addition, three other critical vulnerabilities (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145) with a CVSS score of 9.3 have been identified and are being actively exploited. See below for details.<br><br>According to the <a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/CVE-2026-28302\" target=\"_blank\" rel=\"noreferrer noopener\">SolarWinds Security Advisory dated July 21, 2026<\/a> The vendor has announced a bundle of 15 critical security vulnerabilities in its Managed File Transfer (MFT) software, Serv-U. According to the manufacturer, the vulnerabilities\u2014led by CVE-2026-28302\u2014affect all versions up to and including 15.5.4 HF1. The manufacturer assesses the risk with a CVSS score of <strong>9.1<\/strong>, which indicates a high risk to affected systems. An update to address the vulnerabilities is available.<\/p>\n\t\t\t        <\/div>\n    <\/div>\n<\/div>\n\n\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"400\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability.png\" alt=\"SolarWinds Serv-U: Multiple Critical Vulnerabilities (CVE-2026-28302, CVE-2026-16232)\" class=\"wp-image-9139\" srcset=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability.png 400w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability-300x300.png 300w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability-150x150.png 150w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability-12x12.png 12w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/figure><\/div>\n\n\n<h2 class=\"wp-block-heading\"><strong>The Facts at a Glance<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>CVE-2026-28302 and 14 other vulnerabilities:<\/strong> CVSS 9.1; affects all versions up to 15.5.4 HF1; patch available in version 2026.3<\/li>\n\n\n\n<li><strong>CVE-2026-16232, CVE-2026-62144, CVE-2026-62145:<\/strong> CVSS 9.3, affecting Security Management Server and Multi-Domain Security Management Server (R77.30 through R82.10), Patches available (R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+), actively exploited<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Technical Overview of the Vulnerabilities<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>CVE-2026-28302 and Related Vulnerabilities<\/strong><\/h3>\n\n\n\n<p>According to the SolarWinds advisory, 15 vulnerabilities were documented for this vulnerability complex, under a total of 16 CVE identifiers. The primary identifier is CVE-2026-28302, accompanied by the following additional CVEs: CVE-2026-28304 through CVE-2026-28317, as well as CVE-2026-28321. According to the vendor\u2019s assessment, the high number of identifiers indicates deep-seated security issues in the software.<\/p>\n\n\n\n<p>Affected versions: all releases up to and including <strong>15.5.4 HF1 and below<\/strong>.<\/p>\n\n\n\n<p>The CVSS vector specified by the manufacturer <strong>CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:H\/A:H<\/strong> describes a network-based attack that, while requiring high privileges, is relatively simple. The \u201eScope Changed\u201c (S:C) attribute is particularly critical: it means that a successful attack can extend beyond the application\u2019s boundaries and compromise the underlying operating system. Since both the CVSS vector and score are based exclusively on vendor information at the time of publication and independent verification via the NVD is still pending, administrators should check the details directly in the <a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/CVE-2026-28302\" target=\"_blank\" rel=\"noreferrer noopener\">SolarWinds Trust Center<\/a> Check.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145: Authentication bypass in Check Point SmartConsole<\/strong><\/h3>\n\n\n\n<p>According to <a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk185169\/\" target=\"_blank\" rel=\"noreferrer noopener\">Check Point Security Advisory SK185169<\/a> These three vulnerabilities allow an authentication bypass in the SmartConsole component of Check Point Security Management Server and Multi-Domain Security Management Server. The CVSS score <strong>CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N<\/strong> describes a network-based attack that does not require privileges or user interaction. With a score of <strong>9.3<\/strong> These vulnerabilities pose a critical risk.<\/p>\n\n\n\n<p>Affected versions include Security Management Server and Multi-Domain Security Management Server in releases R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10. Check Point has released patches for the current versions: R82.10 Take 36 and later, R82 Take 118 and later, and R81.20 Take 158 and later.<\/p>\n\n\n\n<p>Particularly critical: According to Check Point, these vulnerabilities <strong>actively utilized<\/strong>. Attackers can gain full administrative access to the management console without authentication, which allows them to completely compromise the managed security infrastructure. This includes access to configuration data, firewall rules, and potentially sensitive network information.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Risk Assessment for Businesses<\/strong><\/h2>\n\n\n\n<p>SolarWinds Serv-U is used in many organizations for the automated and secure exchange of business-critical data. MFT systems are often deeply integrated into core processes, such as data exchange with suppliers, transaction processing, or software distribution. A compromise can therefore have serious consequences, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Data Theft:<\/strong> Unauthorized access to sensitive information exchanged via the server.<\/li>\n\n\n\n<li><strong>Business Interruptions:<\/strong> Manipulation or deletion of data necessary for business operations.<\/li>\n\n\n\n<li><strong>Lateral spread:<\/strong> Using the compromised server as a foothold to attack partner companies via file transfer channels (third-party breach scenario).<\/li>\n<\/ul>\n\n\n\n<p>Although the attack vector for CVE-2026-28302 requires high privileges, this poses a realistic risk in scenarios involving stolen administrator credentials or insider threats. The \u201eScope Change\u201c capability allows attackers to install ransomware, exfiltrate data, or misuse the server as a foothold for further attacks on the network.<\/p>\n\n\n\n<p>The newly disclosed Check Point vulnerabilities (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145) significantly exacerbate the threat landscape, as they do not require elevated privileges and are already being actively exploited. Organizations using Check Point Security Management Server are at immediate risk.<\/p>\n\n\n\n<p>SolarWinds Serv-U has repeatedly been the target of critical security vulnerabilities over the past 24 months: In February 2026, four critical RCE vulnerabilities (CVE-2025-40538 through CVE-2025-40541, CVSS 9.1) were patched in Serv-U 15.5.4; in June 2026, CISA added an actively exploited denial-of-service bug (CVE-2026-28318) to its Known Exploited Vulnerabilities catalog. This cluster of incidents underscores that Serv-U remains a persistent target for attacks and that continuous vendor risk monitoring for SolarWinds products is essential. (Sources: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/critical-solarwinds-serv-u-flaws-offer-root-access-to-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">BleepingComputer, February 2026<\/a>; <a href=\"https:\/\/thehackernews.com\/2026\/06\/cisa-adds-actively-exploited-solarwinds.html\" target=\"_blank\" rel=\"noreferrer noopener\">TheHackerNews, June 2026<\/a>)<\/p>\n\n\n\n<p>Additional reporting requirements apply to organizations in the DACH region: In the event of a confirmed security incident involving access to personal data, the GDPR reporting requirement under Article 33 applies (72-hour deadline for reporting to the competent supervisory authority). Operators of essential services as defined by the NIS 2 Directive\u2014such as those in the healthcare sector, the financial sector, or public administration\u2014are also required to report significant security incidents without delay. The BSI generally recommends immediately updating exposed MFT systems and management consoles in the event of critical vulnerabilities of this severity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Recommended countermeasures<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>For SolarWinds Serv-U (CVE-2026-28302 and related vulnerabilities)<\/strong><\/h3>\n\n\n\n<p>The only measure recommended by the manufacturer is to install the provided update immediately. According to the SolarWinds advisory, the version <strong>2026.3<\/strong> has been released, which is intended to address all of the vulnerabilities described. According to the latest information from the manufacturer, there are no known alternative protective measures or temporary workarounds, which is why this update should be treated as a top priority.<\/p>\n\n\n\n<p>Administrators should note that the version number \u201e2026.3\u201d differs from the previous Serv-U versioning scheme (e.g., 15.x.x). Please keep this in mind when searching for the correct patch in the Customer Portal or on the SolarWinds product page.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>For Check Point Security Management Server (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145)<\/strong><\/h3>\n\n\n\n<p>Due to active exploitation, it is imperative that you install the available patches immediately:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>R82.10:<\/strong> Update to Take 36 or later<\/li>\n\n\n\n<li><strong>R82:<\/strong> Update to Take 118 or higher<\/li>\n\n\n\n<li><strong>R81.20:<\/strong> Update to Take 158 or later<\/li>\n<\/ul>\n\n\n\n<p>For older versions (R77.30 through R81.10), organizations should review the migration path to a supported version or consider temporary network segmentation to reduce the attack surface. Check Point also recommends reviewing audit logs for suspicious authentication attempts or unusual administrative activity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Gain visibility into your own attack surface with LocateRisk<\/strong><\/h2>\n\n\n\n<p>Security incidents like this underscore the need to continuously monitor one\u2019s own external attack surface. Companies often lack a complete overview of which software versions are in use on their publicly accessible systems\u2014especially when it comes to shadow IT, forgotten subdomains, or uncataloged cloud assets that are not included in the internal asset inventory.<\/p>\n\n\n\n<p>LocateRisk helps organizations achieve this transparency:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>External Attack Surface Management (EASM):<\/strong> The platform continuously identifies all externally accessible assets and can detect deployed software\u2014such as SolarWinds Serv-U or Check Point Security Management Server\u2014through service fingerprinting. Version information is compared against up-to-date vulnerability databases, allowing potentially vulnerable systems within the externally visible infrastructure to be identified\u2014serving as the basis for prioritized patch management.<\/li>\n\n\n\n<li><strong>Continuous Vendor Risk Management (C-VRM):<\/strong> The solution continuously assesses the security status of suppliers and service providers. In light of the repeated Serv-U incidents in recent months, C-VRM can alert companies when a critical vendor such as SolarWinds or Check Point is affected by a serious vulnerability\u2014enabling them to proactively respond to changes in the supply chain\u2019s risk profile.<\/li>\n<\/ul>\n\n\n\n<p>By combining these approaches, risks posed by CVE-2026-28302 and the Check Point vulnerabilities can be identified, assessed, and prioritized more quickly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Sources and further information<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SolarWinds Security Advisory:<\/strong> <a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/CVE-2026-28302\" target=\"_blank\" rel=\"noreferrer noopener\">solarwinds.com\/trust-center\/security-advisories\/CVE-2026-28302<\/a><\/li>\n\n\n\n<li><strong>Check Point Security Advisory SK185169:<\/strong> <a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk185169\/\" target=\"_blank\" rel=\"noreferrer noopener\">support.checkpoint.com\/results\/sk\/sk185169\/<\/a><\/li>\n\n\n\n<li><strong>NIST National Vulnerability Database:<\/strong> <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-28302\" target=\"_blank\" rel=\"noreferrer noopener\">nvd.nist.gov\/vuln\/detail\/CVE-2026-28302<\/a><\/li>\n\n\n\n<li><strong>Heise Online:<\/strong> <a href=\"https:\/\/www.heise.de\/news\/Datentransfersoftware-Serv-U-hat-15-kritische-Sicherheitsluecken-11373098.html\" target=\"_blank\" rel=\"noreferrer noopener\">heise.de\/news\/Data-Transfer-Software-Serv-U-Has-15-Critical-Security-Vulnerabilities-11373098.html<\/a><\/li>\n\n\n\n<li><strong>BleepingComputer (February 2026 \u2013 CVE-2025-40538 through -40541):<\/strong> <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/critical-solarwinds-serv-u-flaws-offer-root-access-to-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">bleepingcomputer.com\/news\/security\/critical-solarwinds-serv-u-flaws-offer-root-access-to-servers\/<\/a><\/li>\n\n\n\n<li><strong>TheHackerNews (June 2026 \u2013 CVE-2026-28318, CISA KEV):<\/strong> <a href=\"https:\/\/thehackernews.com\/2026\/06\/cisa-adds-actively-exploited-solarwinds.html\" target=\"_blank\" rel=\"noreferrer noopener\">thehackernews.com\/2026\/06\/cisa-adds-actively-exploited-solarwinds.html<\/a><\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3><strong>Frequently asked questions<\/strong><\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Which versions of SolarWinds Serv-U are affected by CVE-2026-28302?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">According to the SolarWinds advisory, all versions up to and including 15.5.4 HF1 are affected. Organizations running these or older versions should update to the patched version immediately.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Which update addresses the security vulnerabilities described?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">According to the manufacturer, SolarWinds has released version <strong>2026.3<\/strong> has been released, which is intended to address all 15 vulnerabilities in the software suite. Since the version number differs from the previous scheme (15.x.x), administrators should download the patch directly from the SolarWinds Customer Portal or the <a href=\"https:\/\/www.solarwinds.com\/trust-center\/security-advisories\/CVE-2026-28302\" target=\"_blank\" rel=\"noreferrer noopener\">Trust Center<\/a> refer to.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Is CVE-2026-28302 being actively exploited?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">As of the date of the advisory's publication on July 21, 2026, according to the vendor, there were no confirmed reports of active exploitation of these specific vulnerabilities. Administrators should monitor the SolarWinds Trust Center and relevant threat intelligence sources for updates.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Are the Check Point vulnerabilities (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145) being actively exploited?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Yes. According to the Check Point Security Advisory, these vulnerabilities are being actively exploited. Organizations using affected versions of the Security Management Server should install the available patches as a top priority and check their systems for signs of compromise.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Which Check Point versions are affected, and which patches are available?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">This affects Security Management Servers and Multi-Domain Security Management Servers in versions R77.30 through R82.10. Patches are available for R82.10 (Take 36+), R82 (Take 118+), and R81.20 (Take 158+). For older versions, you should consider migrating to a supported version.<\/p><\/div><\/div><\/div><\/div>\n\n\n<p class=\"lr-legal-note\" style=\"margin:32px 0 0;padding-top:16px;border-top:1px solid #e5e7eb;font-size:13px;line-height:1.55;color:#8b93a7;font-style:italic;\">As of July 23, 2026. This post is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.<\/p>\n\n\n<div class=\"wp-block-lr-contact-post-module\">\n\t<div id=\"lr-contact-form\" class=\"wp-block-lr-contact-post-module\">\n\t\t<div id=\"formular\" class=\"content\">\n\t\t\t<div class=\"inner-content\">\n\t\t\t\t<div class=\"column-2 feature-mode\">\n\t\t\t\t\t<h2><br>Request your personal Live-Demo now<\/h2>\n\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div>\n\t\t\t\t\t\t\t\t<p class=\"margin-b-36\">Identify and reduce your cyber risks through a comparable and understandable overview of your IT security. Let our experts advise you and find out how LocateRisk can help you solve your cyber risks.<\/p>\n\t\t\t\t\t\t\t<\/div>\t\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t<\/div> \n\t\t\t\t<div class=\"column-2\">\n\t\t\t\t\t<form action=\"\" class=\"form\" method=\"post\" role=\"form\" novalidate data-trp-original-action=\"\">\n\t\t\t\t\t\t<input type=\"text\" id=\"successmessage\" name=\"successmessage\" value=\"Ihre Registrierung war erfolgreich Ihre Anfrage wurde erfolgreich versendet. Wir haben Ihnen soeben eine Best\u00e4tigungsmail mit einem Aktivierungs-Link zugesendet, um einem Missbrauch Ihrer E-Mail Adresse durch Dritte vorzubeugen. Die Mail wird von sales@locaterisk.com versendet und sollte sich i n wenigen Minuten in Ihrem Posteingang finden.\" hidden>\n\t\t\t\t\t\t<input type=\"text\" id=\"errormessage\" name=\"errormessage\" value=\"Da ist wohl etwas schief gelaufen. Bitte probieren Sie es erneut oder nehmen Sie direkt mit uns Kontakt auf\" hidden>\n\t\t\t\t\t\t<input type=\"text\" id=\"slug\" name=\"slug\" value=\"solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\" hidden>\n\t\t\t\t\t\t<input type=\"text\" id=\"pageurl\" name=\"pageurl\" value=\"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts\/9189\" hidden>\n\n\t\t\t\t\t\t\t\t\t\t\t\t\t<input\n\t\t\t\t\t\t\t\ttype=\"text\"\n\t\t\t\t\t\t\t\tid=\"name\"\n\t\t\t\t\t\t\t\tname=\"name\"\n\t\t\t\t\t\t\t\tplaceholder=\"first name\"\n\t\t\t\t\t\t\t\trequired\tmaxlength=\"50\"\/>\n\n\t\t\t\t\t\t\t<input\n\t\t\t\t\t\t\t\ttype=\"text\"\n\t\t\t\t\t\t\t\tid=\"surname\"\n\t\t\t\t\t\t\t\tname=\"surname\"\n\t\t\t\t\t\t\t\tplaceholder=\"last name\"\n\t\t\t\t\t\t\t\trequired\n\t\t\t\t\t\t\t\tmaxlength=\"50\"\/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<input\n\t\t\t\t\t\t\ttype=\"email\"\n\t\t\t\t\t\t\tid=\"email\"\n\t\t\t\t\t\t\tname=\"email\"\n\t\t\t\t\t\t\tplaceholder=\"Email\"\n\t\t\t\t\t\t\trequired\n\t\t\t\t\t\t\tmaxlength=\"50\"\/>\n\n\t\t\t\t\t\t<input\n\t\t\t\t\t\t\ttype=\"text\"\n\t\t\t\t\t\t\tid=\"phone\"\n\t\t\t\t\t\t\tname=\"phone\"\n\t\t\t\t\t\t\tplaceholder=\"phone\"\n\t\t\t\t\t\t\trequired\n\t\t\t\t\t\t\tmaxlength=\"50\"\/>\n\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t<h6 class=\"error-message\" hidden>...<\/h6>\n\t\t\t\t\t\t<div class=\"checkbox_container\">\n\t\t\t\t\t\t\t<div class=\"checkbox\">\n\t\t\t\t\t\t\t\t<input\n\t\t\t\t\t\t\t\t\ttype=\"checkbox\"\n\t\t\t\t\t\t\t\t\tid=\"checkbox\"\n\t\t\t\t\t\t\t\t\tname=\"checkbox\" \/>\n\n\t\t\t\t\t\t\t\t<label for=\"checkbox\"><\/label>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<p class=\"translation-block\">I agree with the <a href=\"https:\/\/locaterisk.com\/en\/privacy-policy\/\" target=\"_self\">privacy policy<\/a>.<\/p> \n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\n\t\t\t\t\t<div class=\"g-recaptcha\" data-sitekey=\"6LdErNoZAAAAAD1Re2jNxtDFfcDaL9iED5MRBzjR\" data-callback=\"verifyRecaptchaCallback\" data-expired-callback=\"expiredRecaptchaCallback\"><\/div>\n\t\t\t\t\t<input type=\"hidden\" name=\"g-recaptcha-response\" data-recaptcha \/>\n\n\t\t\t\t\t\t<button class=\"lr-button-link\" type=\"submit\"> Request a Demo<\/button>\n\t\t\t\t\t<input type=\"hidden\" name=\"trp-form-language\" value=\"en\"\/><\/form>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/div>\n\t\n\t<\/div>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity is-style-wide\"\/>\n\n\n\n<div class=\"wp-block-lr-contact-module\"><div class=\"content\"><h2>Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!<\/h2><div class=\"contact-info-row\"><div class=\"contact-person-info\"><div class=\"avatar\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2025\/06\/Lukas_Baumann_LocateRisk-300.png\"><\/div><p><span class=\"text before\">Your personal consultant<\/span><span class=\"bold name\"><strong>Lukas<\/strong><\/span> <span class=\"lastname\"><strong>Baumann<strong><\/strong><\/strong><\/span><strong><strong><span class=\"separator\"><\/span><span class=\"role\">CEO<\/span><\/strong><\/strong><\/p><\/div><p class=\"bold phone\"><strong><strong>+49 6151 6290246<\/strong><\/strong><\/p><strong><strong><a class=\"pr-1\" href=\"mailto:%20sales@locaterisk.com\">Get in Touch Now<\/a><\/strong><\/strong><\/div><\/div><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-lr-footer-module lr-footer-block\"><div class=\"content\"><div class=\"column0\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/assets\/img\/lr-logo.svg\"\/><\/div><div class=\"categories\"><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/\">Home<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/blog\/\">Blog<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/know\/\">Knowledge<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/about\/\">About Us<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/contact\/\">Contact<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/legal-notice\/\">Legal Notice<\/a><\/div><div class=\"categories-break\"><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/privacy-policy\/\">Privacy<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/files\/agb.pdf\">General Terms and Conditions<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/jobs\/\">Jobs<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/app.secfix.com\/trust\/locaterisk\/d1e7d433b33643aea1880bfbfeab9f60\">Trust Center<\/a><\/div><\/div><div class=\"social\"><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/locaterisk\/\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/10\/gruppe-230@3x.png\"\/><\/a><\/div><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/www.instagram.com\/locaterisk\/\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Instagram.png\"\/><\/a><\/div><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/twitter.com\/locaterisk\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/twitter.png\"\/><\/a><\/div><\/div><div class=\"description\"><h6>\u00a9 LocateRisk 2026<\/h6><\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>On July 21, 2026, 15 critical vulnerabilities in SolarWinds Serv-U (CVE-2026-28302) were disclosed. In addition, CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 (CVSS 9.3) were disclosed. Updates are available.<\/p>","protected":false},"author":13,"featured_media":9139,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[632],"tags":[744,747,748,746,117,87,743,16,745],"lr_blog_topic":[837],"class_list":["post-9189","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-news","tag-cve-2026-28302","tag-cve-2026-28304","tag-cve-2026-28305","tag-managed-file-transfer","tag-patch-management","tag-schwachstellenmanagement","tag-serv-u","tag-sicherheitsluecke","tag-solarwinds","lr_blog_topic-schwachstellen-advisories"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SolarWinds Serv-U: mehrere kritische L\u00fccken \u2013 Update empfohlen<\/title>\n<meta name=\"description\" content=\"Am 21. Juli 2026 wurden 15 kritische Schwachstellen in SolarWinds Serv-U (CVE-2026-28302) ver\u00f6ffentlicht. Zus\u00e4tzlich wurden CVE-2026-16232, CVE-2026-62144 und CVE-2026-62145 (CVSS 9.3) bekannt. Updates verf\u00fcgbar.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/locaterisk.com\/en\/solarwinds-servu-15-critical-security-vulnerabilities-cve-2026-28302\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SolarWinds Serv-U: mehrere kritische L\u00fccken \u2013 Update empfohlen\" \/>\n<meta property=\"og:description\" content=\"Am 21. Juli 2026 wurden 15 kritische Schwachstellen in SolarWinds Serv-U (CVE-2026-28302) ver\u00f6ffentlicht. Zus\u00e4tzlich wurden CVE-2026-16232, CVE-2026-62144 und CVE-2026-62145 (CVSS 9.3) bekannt. Updates verf\u00fcgbar.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/locaterisk.com\/en\/solarwinds-servu-15-critical-security-vulnerabilities-cve-2026-28302\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-22T09:33:45+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-23T08:44:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Kristina Hoinkis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kristina Hoinkis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/\"},\"author\":{\"name\":\"Kristina Hoinkis\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/person\\\/68f3857c15afa8ff59c545848dddcc32\"},\"headline\":\"SolarWinds Serv-U: mehrere kritische Sicherheitsl\u00fccken (CVE-2026-28302, CVE-2026-16232)\",\"datePublished\":\"2026-07-22T09:33:45+00:00\",\"dateModified\":\"2026-07-23T08:44:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/\"},\"wordCount\":1678,\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/third-party-vulnerability.png\",\"keywords\":[\"CVE-2026-28302\",\"CVE-2026-28304\",\"CVE-2026-28305\",\"Managed File Transfer\",\"Patch Management\",\"Schwachstellenmanagement\",\"Serv-U\",\"Sicherheitsl\u00fccke\",\"SolarWinds\"],\"articleSection\":[\"Cybersecurity News\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/\",\"name\":\"SolarWinds Serv-U: mehrere kritische L\u00fccken \u2013 Update empfohlen\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/third-party-vulnerability.png\",\"datePublished\":\"2026-07-22T09:33:45+00:00\",\"dateModified\":\"2026-07-23T08:44:25+00:00\",\"description\":\"Am 21. Juli 2026 wurden 15 kritische Schwachstellen in SolarWinds Serv-U (CVE-2026-28302) ver\u00f6ffentlicht. Zus\u00e4tzlich wurden CVE-2026-16232, CVE-2026-62144 und CVE-2026-62145 (CVSS 9.3) bekannt. Updates verf\u00fcgbar.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/#primaryimage\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/third-party-vulnerability.png\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/third-party-vulnerability.png\",\"width\":400,\"height\":400,\"caption\":\"third-party-vulnerability\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SolarWinds Serv-U: mehrere kritische Sicherheitsl\u00fccken (CVE-2026-28302, CVE-2026-16232)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/person\\\/68f3857c15afa8ff59c545848dddcc32\",\"name\":\"Kristina Hoinkis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"caption\":\"Kristina Hoinkis\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SolarWinds Serv-U: Multiple Critical Vulnerabilities\u2014Update Recommended","description":"On July 21, 2026, 15 critical vulnerabilities in SolarWinds Serv-U (CVE-2026-28302) were disclosed. In addition, CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 (CVSS 9.3) were disclosed. Updates are available.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/locaterisk.com\/en\/solarwinds-servu-15-critical-security-vulnerabilities-cve-2026-28302\/","og_locale":"en_US","og_type":"article","og_title":"SolarWinds Serv-U: mehrere kritische L\u00fccken \u2013 Update empfohlen","og_description":"Am 21. Juli 2026 wurden 15 kritische Schwachstellen in SolarWinds Serv-U (CVE-2026-28302) ver\u00f6ffentlicht. Zus\u00e4tzlich wurden CVE-2026-16232, CVE-2026-62144 und CVE-2026-62145 (CVSS 9.3) bekannt. Updates verf\u00fcgbar.","og_url":"https:\/\/locaterisk.com\/en\/solarwinds-servu-15-critical-security-vulnerabilities-cve-2026-28302\/","og_site_name":"LocateRisk","article_published_time":"2026-07-22T09:33:45+00:00","article_modified_time":"2026-07-23T08:44:25+00:00","og_image":[{"width":400,"height":400,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability.png","type":"image\/png"}],"author":"Kristina Hoinkis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Kristina Hoinkis","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/#article","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/"},"author":{"name":"Kristina Hoinkis","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/person\/68f3857c15afa8ff59c545848dddcc32"},"headline":"SolarWinds Serv-U: mehrere kritische Sicherheitsl\u00fccken (CVE-2026-28302, CVE-2026-16232)","datePublished":"2026-07-22T09:33:45+00:00","dateModified":"2026-07-23T08:44:25+00:00","mainEntityOfPage":{"@id":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/"},"wordCount":1678,"publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"image":{"@id":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/#primaryimage"},"thumbnailUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability.png","keywords":["CVE-2026-28302","CVE-2026-28304","CVE-2026-28305","Managed File Transfer","Patch Management","Schwachstellenmanagement","Serv-U","Sicherheitsl\u00fccke","SolarWinds"],"articleSection":["Cybersecurity News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/","url":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/","name":"SolarWinds Serv-U: Multiple Critical Vulnerabilities\u2014Update Recommended","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/#primaryimage"},"image":{"@id":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/#primaryimage"},"thumbnailUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability.png","datePublished":"2026-07-22T09:33:45+00:00","dateModified":"2026-07-23T08:44:25+00:00","description":"On July 21, 2026, 15 critical vulnerabilities in SolarWinds Serv-U (CVE-2026-28302) were disclosed. In addition, CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 (CVSS 9.3) were disclosed. Updates are available.","breadcrumb":{"@id":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/#primaryimage","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability.png","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/third-party-vulnerability.png","width":400,"height":400,"caption":"third-party-vulnerability"},{"@type":"BreadcrumbList","@id":"https:\/\/locaterisk.com\/de\/solarwinds-serv-u-15-kritische-sicherheitsluecken-cve-2026-28302\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/locaterisk.com\/"},{"@type":"ListItem","position":2,"name":"SolarWinds Serv-U: mehrere kritische Sicherheitsl\u00fccken (CVE-2026-28302, CVE-2026-16232)"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]},{"@type":"Person","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/person\/68f3857c15afa8ff59c545848dddcc32","name":"Kristina Hoinkis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","caption":"Kristina Hoinkis"}}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts\/9189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/comments?post=9189"}],"version-history":[{"count":2,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts\/9189\/revisions"}],"predecessor-version":[{"id":9192,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts\/9189\/revisions\/9192"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media\/9139"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=9189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/categories?post=9189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/tags?post=9189"},{"taxonomy":"lr_blog_topic","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/lr_blog_topic?post=9189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}