AI description
CVE-2026-28304 is identified as a remote code execution (RCE) vulnerability impacting SolarWinds Serv-U, a multi-protocol file server. This flaw allows for the arbitrary execution of code remotely as root. While the vulnerability affects both Windows and other operating systems, its impact is noted to be lower in Windows deployments. This vulnerability is often mentioned in conjunction with CVE-2026-28311, another RCE vulnerability also affecting SolarWinds Serv-U. Organizations utilizing SolarWinds Serv-U are advised to apply security updates to address these issues.
- Description
- SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
- Source
- psirt@solarwinds.com
- NVD status
- Analyzed
- Products
- serv-u
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@solarwinds.com
- CWE-284
- Hype score
- Not currently trending
SolarWinds Serv-U 2026.3 patches 15 vulnerabilities — 14 Critical (CVSS 9.1) enabling privilege escalation to root RCE. List of all vulnerabilities reported in the latest security advisory: 🔵 CVE-2026-28302 🔵 CVE-2026-28304 🔵 CVE-2026-28305 🔵 CVE-2026-28306 🔵 CV
@techepages
22 Jul 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️⚠️ CVE-2026-28304 (CVSS 9.1) + CVE-2026-28314 (CVSS 9.1): SolarWinds Serv-U patch wave — authenticated IDOR/priv-esc paths to root RCE; CVE-2026-28314 needs only user auth for account takeover (≤15.5.4 HF1; fix Serv-U 2026.3). 🔗FOFA Link: https://t.co/xAQaoGRkWh
@fofabot
22 Jul 2026
1665 Impressions
5 Retweets
16 Likes
8 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6CC041DF-D376-4F82-ABDD-61E3898A1C2A",
"versionEndExcluding": "2026.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]