CVE-2026-28315: exploitation status and patch state
CVE-2026-28315 · CVSS 6.2 MEDIUM
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.
Is CVE-2026-28315 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.