Wednesday , August 12 2026
SolarWinds

SolarWinds Patches 15 Critical Serv-U Flaws

SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix 15 problems that could let attackers get higher access and, in some cases, run code with root user rights.

These fixes came in Serv-U version 2026.3, released on July 21, 2026, as part of the company’s ongoing work to fix serious flaws found in its bug bounty program.

AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

A serious security flaw in Zoom might let a hacker take control of someone else's device in a live meeting...
Read More
AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

Hacker Actively Exploit SonicWall and SharePoint Flaws

The CISA in the U.S. has added two important SonicWall SMA1000 flaws—CVE-2026-15409 and CVE-2026-15410-to its list of Known Exploited Vulnerabilities...
Read More
Hacker Actively Exploit SonicWall and SharePoint Flaws

Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

A joint warning from the FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the U.S. Secret Service,...
Read More
Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Attackers penetrated into IEH Corporation, a US defense and airspace firm, using a fake link that looked like a real...
Read More
Hackers accessed a US defense manufacturer’s Microsoft 365 account via phishing.

Google Play Apps Utilize Stealth Loaders to Spread Anatsa Banking Malware

Android users are reminded that a known app store listing can hold a money threat. Researchers found harmful loaders on...
Read More
Google Play Apps Utilize Stealth Loaders to Spread Anatsa Banking Malware

Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

The gentlemen ransomware group targets various industries of Bangladesh. In an advisory Bangladesh e-Government Computer Incident Response Team (BGD e-GOV...
Read More
Bangladeshi org listed “the Gentlemen’ ransomware victim list: CIRT warns

Around 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer

A group of almost 800 harmful packages was added to the npm registry in a new effort to spread malware...
Read More
Around 800 Malicious npm Packages Distribute Cross-Platform RAT and Infostealer

Google Chrome 151 Update Fixes 41 Flaws, 6 Critical

Google has launched Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update brings 41 security...
Read More
Google Chrome 151 Update Fixes 41 Flaws, 6 Critical

Swiss gov.t SharePoint incident compromised 200 accounts

Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. The...
Read More
Swiss gov.t SharePoint incident compromised 200 accounts

Azad president, Secretary Post Heads to Contest: ISACA Dhaka Chapter Election

The ISACA Dhaka Chapter Election for 2026–2028 will take place on 8, August-2026. Most of the executive roles are likely...
Read More
Azad president, Secretary Post Heads to Contest: ISACA Dhaka Chapter Election

The fixed security flaws are tracked with different CVE numbers, like CVE-2026-28302 to CVE-2026-28321. Most of them have a high severity score of 9.1, showing a serious risk. Many of these problems come from weak direct object references (IDOR) and faulty access controls.

They could allow logged-in attackers, especially those with domain or admin access, to gain higher privileges, change how the application works, and finally run any code with full permissions.

Two of the most severe vulnerabilities, CVE-2026-28304 and CVE-2026-28311, involve remote code execution. Successful exploitation could allow attackers to run malicious commands on affected systems remotely.

Vulnerabilities can let lower-level users or groups become system administrators, skipping past the intended access limits.

SolarWinds Patches Serv-U Vulnerabilities

Certain flaws can cause privilege escalation, account takeover, and SMTP hijacking. For example, CVE-2026-28313 lets attackers use an IDOR problem to take over user accounts by changing SMTP settings.

CVE-2026-28315 is another flaw. It allows harmful scripts to be stored, which can show sensitive admin session info or cause session theft.

Many of these security holes need a certain type of access, like a domain admin account or permissions for a group, according to SolarWinds.

CVE ID Vulnerability Type Severity
CVE-2026-28302 IDOR Critical (9.1)
CVE-2026-28304 Remote Code Execution Critical (9.1)
CVE-2026-28305 IDOR Critical (9.1)
CVE-2026-28306 Privilege Escalation Critical (9.1)
CVE-2026-28307 Privilege Escalation Critical (9.1)
CVE-2026-28308 IDOR Critical (9.1)
CVE-2026-28309 Broken Access Control Critical (9.1)
CVE-2026-28310 Privilege Escalation Critical (9.1)
CVE-2026-28311 Remote Code Execution Critical (9.1)
CVE-2026-28312 Privilege Escalation Critical (9.1)
CVE-2026-28313 IDOR Critical (9.1)
CVE-2026-28314 IDOR Critical (9.1)
CVE-2026-28315 Stored XSS Medium (6.2)
CVE-2026-28316 IDOR Critical (9.1)
CVE-2026-28317 IDOR Critical (9.1)
CVE-2026-28321 Broken Access Control Critical (9.1)

In real life, attackers often connect these weaknesses after breaking in at first. This makes these problems very risky for businesses.

The company said that the impact is usually less in Windows compared to Linux, where root access is more risky. Besides fixing vulnerabilities, Serv-U 2026.3 brings several security and user-friendly updates.

Content Security Policies are now stronger to lower the chances of code injection attacks. New security headers like Cross-Origin policies and Permissions-Policy have also been added or made adjustable. The update brings OpenSSL 3.0.21 for better security and performance.

Additional upgrades include better multi-factor authentication for Active Directory and LDAP users, easier file-sharing processes, and more reliable client connections. These changes aim to boost security and make the platform work better.

SolarWinds thanked the Intigriti bug bounty program for sharing the security problems in a responsible way and for helping fix them.

The company is asking all users to upgrade to Serv-U 2026.3 now. Older versions are becoming outdated and will not get security updates anymore.

Timely updates are very important because of the serious flaws in Serv-U that many businesses use for file transfers. This helps stop possible attacks and lowers risks.

Check Also

Cursor

Cursor, SonicWall, SharePoint 0-day exploited to the wild

A serious security flaw in Cursor, a popular AI code editor used by more than …