« Volver al listado

Solarwinds

Solarwinds Serv-u: vulnerabilidades y CVE

Solarwinds Serv-u tiene 55 vulnerabilidades publicadas, 23 de ellas en los últimos 12 meses. 19 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE55
Últimos 12 meses23
Críticas19
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-28318Alta (7.5)1.9%⚠ Explotación activa4 jun 2026
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in…
CVE-2024-28995Alta (7.5)100%⚠ Explotación activa6 jun 2024
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
CVE-2021-35247Media (5.3)3.5%⚠ Explotación activa10 ene 2022
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No…
CVE-2021-35211Crítica (10)91%⚠ Explotación activa14 jul 2021
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-28321Crítica (9.1)0.58%—21 jul 2026
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator…
CVE-2026-28317Crítica (9.1)0.50%—21 jul 2026
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows…
CVE-2026-28316Crítica (9.1)2.1%—21 jul 2026
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue…
CVE-2026-28315Media (6.2)0.52%—21 jul 2026
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.
CVE-2026-28314Crítica (9.1)0.62%—21 jul 2026
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
CVE-2026-28313Crítica (9.1)0.50%—21 jul 2026
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
CVE-2026-28312Crítica (9.1)0.58%—21 jul 2026
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
CVE-2026-28310Crítica (9.1)0.50%—21 jul 2026
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
CVE-2026-28309Crítica (9.1)0.50%—21 jul 2026
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
CVE-2026-28308Crítica (9.1)0.79%—21 jul 2026
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
CVE-2026-28307Crítica (9.1)0.50%—21 jul 2026
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
CVE-2026-28306Crítica (9.1)0.50%—21 jul 2026
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
CVE-2026-28305Crítica (9.1)0.79%—21 jul 2026
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home…
CVE-2026-28304Crítica (9.1)0.79%—21 jul 2026
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
CVE-2026-28302Crítica (9.1)0.79%—21 jul 2026
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The…
CVE-2026-28318Alta (7.5)1.9%⚠ Explotación activa4 jun 2026
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in…
CVE-2025-40541Alta (7.2)0.58%—24 feb 2026
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative…
CVE-2025-40540Alta (7.2)0.45%—24 feb 2026
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse.…
CVE-2025-40539Alta (7.2)0.45%—24 feb 2026
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse.…
CVE-2025-40538Alta (7.2)0.51%—24 feb 2026
A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group…
CVE-2025-40549Crítica (9.1)1.1%—18 nov 2025
A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative…
CVE-2025-40548Crítica (9.1)0.70%—18 nov 2025
A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows…
CVE-2025-40547Crítica (9.1)0.89%—18 nov 2025
A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows…
CVE-2024-45712Media (5.4)0.38%—15 abr 2025
SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session.…
CVE-2024-45714Media (4.1)0.89%—16 oct 2024
Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.
CVE-2024-45711Alta (8.8)6.3%—16 oct 2024
SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and…
CVE-2024-28995Alta (7.5)100%⚠ Explotación activa6 jun 2024
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
CVE-2024-28072Media (4.9)0.64%—3 may 2024
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
CVE-2024-28073Alta (7.2)1.1%—17 abr 2024
SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.
CVE-2023-40053Media (5)0.83%—6 dic 2023
A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1005 Data from Local System1
  3. T1059 Command and Scripting Interpreter1
  4. T1499.004 Application or System Exploitation1
  5. T1565.002 Transmitted Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Solarwinds