SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix 15 problems that could let attackers get higher access and, in some cases, run code with root user rights.
These fixes came in Serv-U version 2026.3, released on July 21, 2026, as part of the company’s ongoing work to fix serious flaws found in its bug bounty program.
The fixed security flaws are tracked with different CVE numbers, like CVE-2026-28302 to CVE-2026-28321. Most of them have a high severity score of 9.1, showing a serious risk. Many of these problems come from weak direct object references (IDOR) and faulty access controls.
They could allow logged-in attackers, especially those with domain or admin access, to gain higher privileges, change how the application works, and finally run any code with full permissions.
Two of the most severe vulnerabilities, CVE-2026-28304 and CVE-2026-28311, involve remote code execution. Successful exploitation could allow attackers to run malicious commands on affected systems remotely.
Vulnerabilities can let lower-level users or groups become system administrators, skipping past the intended access limits.
SolarWinds Patches Serv-U Vulnerabilities
Certain flaws can cause privilege escalation, account takeover, and SMTP hijacking. For example, CVE-2026-28313 lets attackers use an IDOR problem to take over user accounts by changing SMTP settings.
CVE-2026-28315 is another flaw. It allows harmful scripts to be stored, which can show sensitive admin session info or cause session theft.
Many of these security holes need a certain type of access, like a domain admin account or permissions for a group, according to SolarWinds.
| CVE ID | Vulnerability Type | Severity |
|---|---|---|
| CVE-2026-28302 | IDOR | Critical (9.1) |
| CVE-2026-28304 | Remote Code Execution | Critical (9.1) |
| CVE-2026-28305 | IDOR | Critical (9.1) |
| CVE-2026-28306 | Privilege Escalation | Critical (9.1) |
| CVE-2026-28307 | Privilege Escalation | Critical (9.1) |
| CVE-2026-28308 | IDOR | Critical (9.1) |
| CVE-2026-28309 | Broken Access Control | Critical (9.1) |
| CVE-2026-28310 | Privilege Escalation | Critical (9.1) |
| CVE-2026-28311 | Remote Code Execution | Critical (9.1) |
| CVE-2026-28312 | Privilege Escalation | Critical (9.1) |
| CVE-2026-28313 | IDOR | Critical (9.1) |
| CVE-2026-28314 | IDOR | Critical (9.1) |
| CVE-2026-28315 | Stored XSS | Medium (6.2) |
| CVE-2026-28316 | IDOR | Critical (9.1) |
| CVE-2026-28317 | IDOR | Critical (9.1) |
| CVE-2026-28321 | Broken Access Control | Critical (9.1) |
In real life, attackers often connect these weaknesses after breaking in at first. This makes these problems very risky for businesses.
The company said that the impact is usually less in Windows compared to Linux, where root access is more risky. Besides fixing vulnerabilities, Serv-U 2026.3 brings several security and user-friendly updates.
Content Security Policies are now stronger to lower the chances of code injection attacks. New security headers like Cross-Origin policies and Permissions-Policy have also been added or made adjustable. The update brings OpenSSL 3.0.21 for better security and performance.
Additional upgrades include better multi-factor authentication for Active Directory and LDAP users, easier file-sharing processes, and more reliable client connections. These changes aim to boost security and make the platform work better.
SolarWinds thanked the Intigriti bug bounty program for sharing the security problems in a responsible way and for helping fix them.
The company is asking all users to upgrade to Serv-U 2026.3 now. Older versions are becoming outdated and will not get security updates anymore.
Timely updates are very important because of the serious flaws in Serv-U that many businesses use for file transfers. This helps stop possible attacks and lowers risks.
InfoSecBulletin Cybersecurity for mankind
