SOLARWINDS addressed three critical vulnerabilities in their Serv-U software on July 21, 2026, which can lead to privilege escalation and remote code execution (RCE). These vulnerabilities are rated 9.1 on the critical scale and require existing privileges to exploit. The affected versions include Serv-U 15.5.4 HF1 and below, while the updated version, Serv-U 2026.3, resolves all issues.
The vulnerabilities particularly affect Linux systems and have the potential to compromise sensitive data through managed file transfers. The flaws are described as follows:
1. **CVE-2026-28307**: Allows domain users to gain admin rights.
2. **CVE-2026-28308**: Enables RCE via insecure direct object references, requiring domain admin access.
3. **CVE-2026-28321**: Weak access controls permitting arbitrary file operations, leading to root-level code execution.
Cybersecurity experts recommend upgrading to the latest version immediately or implementing strict access controls and restricting internet exposure to minimize risks.