Vulnerabilities · 49 days ago
Serv-U’s delegated admin model is not a safety boundary. If a domain or group admin account is compromised, these flaws let that account cross into system or root control, so role separation does not contain the blast radius.
SolarWinds and NCSC say Serv-U had 15 fixed flaws, mostly IDOR and broken access control, plus stored XSS and related authorization bugs. The issues can support privilege escalation to system administrator or root, remote code execution, SMTP session hijacking, account takeover, and admin session compromise. SolarWinds says the fix is Serv-U 2026.3, and the advisory describes the problem as strongest in Evil Admin scenarios that start from already-authenticated high privilege access.
CVEs in this update
15 CVEs
14 critical · 0 high · 1 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-28302 · 9.1 CRITICAL
Showing the top 10 by KEV, EPSS, and severity.
2 sources covering this story
Kwetsbaarheden verholpen in SolarWinds Serv-U
De kwetsbaarheden in SolarWinds Serv-U betreffen voornamelijk insecure direct object reference (IDOR) en broken access control.
Risolte 16 vulnerabilità di sicurezza, di cui 15 con gravità “critica” nel prodotto Serv-U di SolarWinds.
Part of the PlainSec briefing for 2026-07-27