CVE-2026-28304

Published Jul 21, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-28304 is identified as a remote code execution (RCE) vulnerability impacting SolarWinds Serv-U, a multi-protocol file server. This flaw allows for the arbitrary execution of code remotely as root. While the vulnerability affects both Windows and other operating systems, its impact is noted to be lower in Windows deployments. This vulnerability is often mentioned in conjunction with CVE-2026-28311, another RCE vulnerability also affecting SolarWinds Serv-U. Organizations utilizing SolarWinds Serv-U are advised to apply security updates to address these issues.

Description
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
Source
psirt@solarwinds.com
NVD status
Analyzed
Products
serv-u

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
6
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@solarwinds.com
CWE-284

Social media

Hype score
Not currently trending

Configurations