Solarwinds
Solarwinds Serv-u: vulnerabilidades y CVE
Solarwinds Serv-u tiene 55 vulnerabilidades publicadas, 23 de ellas en los últimos 12 meses. 19 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE55
Últimos 12 meses23
Críticas19
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-28318 | Alta (7.5) | 1.9% | ⚠ Explotación activa | 4 jun 2026 | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in… |
| CVE-2024-28995 | Alta (7.5) | 100% | ⚠ Explotación activa | 6 jun 2024 | SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. |
| CVE-2021-35247 | Media (5.3) | 3.5% | ⚠ Explotación activa | 10 ene 2022 | Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No… |
| CVE-2021-35211 | Crítica (10) | 91% | ⚠ Explotación activa | 14 jul 2021 | Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-28321 | Crítica (9.1) | 0.58% | — | 21 jul 2026 | SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator… |
| CVE-2026-28317 | Crítica (9.1) | 0.50% | — | 21 jul 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows… |
| CVE-2026-28316 | Crítica (9.1) | 2.1% | — | 21 jul 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue… |
| CVE-2026-28315 | Media (6.2) | 0.52% | — | 21 jul 2026 | SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account. |
| CVE-2026-28314 | Crítica (9.1) | 0.62% | — | 21 jul 2026 | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. |
| CVE-2026-28313 | Crítica (9.1) | 0.50% | — | 21 jul 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments. |
| CVE-2026-28312 | Crítica (9.1) | 0.58% | — | 21 jul 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments. |
| CVE-2026-28310 | Crítica (9.1) | 0.50% | — | 21 jul 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments. |
| CVE-2026-28309 | Crítica (9.1) | 0.50% | — | 21 jul 2026 | SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments. |
| CVE-2026-28308 | Crítica (9.1) | 0.79% | — | 21 jul 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments. |
| CVE-2026-28307 | Crítica (9.1) | 0.50% | — | 21 jul 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments. |
| CVE-2026-28306 | Crítica (9.1) | 0.50% | — | 21 jul 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments. |
| CVE-2026-28305 | Crítica (9.1) | 0.79% | — | 21 jul 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home… |
| CVE-2026-28304 | Crítica (9.1) | 0.79% | — | 21 jul 2026 | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments. |
| CVE-2026-28302 | Crítica (9.1) | 0.79% | — | 21 jul 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The… |
| CVE-2026-28318 | Alta (7.5) | 1.9% | ⚠ Explotación activa | 4 jun 2026 | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in… |
| CVE-2025-40541 | Alta (7.2) | 0.58% | — | 24 feb 2026 | An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative… |
| CVE-2025-40540 | Alta (7.2) | 0.45% | — | 24 feb 2026 | A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse.… |
| CVE-2025-40539 | Alta (7.2) | 0.45% | — | 24 feb 2026 | A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse.… |
| CVE-2025-40538 | Alta (7.2) | 0.51% | — | 24 feb 2026 | A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group… |
| CVE-2025-40549 | Crítica (9.1) | 1.1% | — | 18 nov 2025 | A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative… |
| CVE-2025-40548 | Crítica (9.1) | 0.70% | — | 18 nov 2025 | A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows… |
| CVE-2025-40547 | Crítica (9.1) | 0.89% | — | 18 nov 2025 | A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows… |
| CVE-2024-45712 | Media (5.4) | 0.38% | — | 15 abr 2025 | SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session.… |
| CVE-2024-45714 | Media (4.1) | 0.89% | — | 16 oct 2024 | Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload. |
| CVE-2024-45711 | Alta (8.8) | 6.3% | — | 16 oct 2024 | SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and… |
| CVE-2024-28995 | Alta (7.5) | 100% | ⚠ Explotación activa | 6 jun 2024 | SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. |
| CVE-2024-28072 | Media (4.9) | 0.64% | — | 3 may 2024 | A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly. |
| CVE-2024-28073 | Alta (7.2) | 1.1% | — | 17 abr 2024 | SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited. |
| CVE-2023-40053 | Media (5) | 0.83% | — | 6 dic 2023 | A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Solarwinds
Orion Platform · 49Access Rights Manager · 33Solarwinds Platform · 27WEB Help Desk · 22Serv-u File Server · 20Database Performance Analyzer · 11Serv-u FTP Server · 11Observability Self-hosted · 10Orion Network Performance Monitor · 9N-central · 9Network Performance Monitor · 8Dameware Mini Remote Control · 8