Remote Code Execution Vulnerability in SolarWinds Serv-U
CVE-2026-28304

4.7MEDIUM

Key Information:

Vendor

Solarwinds

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-28304?

CVE-2026-28304 is a remote code execution vulnerability found in SolarWinds Serv-U, a software solution designed for secure file transfer and remote access, widely used by organizations to facilitate secure connections for data sharing. This vulnerability allows an attacker to execute arbitrary code on the server remotely with root privileges. This can lead to unauthorized access, control over the system, and potential compromise of sensitive data. While the risk is lower in Windows environments, the impact could still be significant for organizations relying on Serv-U for critical operations, as it opens avenues for further exploitation, including data breaches or the installation of malware.

Potential impact of CVE-2026-28304

  1. Unauthorized Access: Exploitation of this vulnerability can give attackers root-level access to the system, allowing them to manipulate data, access confidential information, and take control of server functionalities.

  2. Data Breaches: The ability to execute arbitrary code can lead to severe data exfiltration issues, where sensitive information may be stolen, leading to potential financial loss and reputational damage to the organization.

  3. System Compromise: Remote code execution vulnerabilities pose a risk of allowing malware to be deployed within the network, which can lead to further compromises, including the installation of ransomware or other malicious software, amplifying the security threat landscape for the affected organization.

Affected Version(s)

Serv-U 15.5.4 HF1 and below

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Intigriti Bug Bounty Program
.