Vulnerabilities · 49 days ago

Serv-U Admin Roles Do Not Contain Blast Radius

Serv-U’s delegated admin model is not a safety boundary. If a domain or group admin account is compromised, these flaws let that account cross into system or root control, so role separation does not contain the blast radius.

SolarWinds and NCSC say Serv-U had 15 fixed flaws, mostly IDOR and broken access control, plus stored XSS and related authorization bugs. The issues can support privilege escalation to system administrator or root, remote code execution, SMTP session hijacking, account takeover, and admin session compromise. SolarWinds says the fix is Serv-U 2026.3, and the advisory describes the problem as strongest in Evil Admin scenarios that start from already-authenticated high privilege access.

CVEs in this update

15 CVEs

14 critical · 0 high · 1 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-28302 · 9.1 CRITICAL

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-27

Editions

Related stories