Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.58% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations. | |
| Analizada | Crítica (9.1) | 0.50% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 2.1% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments. | |
| Analizada | Media (6.2) | 0.52% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account. | |
| Analizada | Crítica (9.1) | 0.62% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 0.50% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 0.58% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 0.50% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 0.50% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 0.79% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 0.50% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 0.50% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 0.79% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 0.79% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments. | |
| Analizada | Crítica (9.1) | 0.79% | — | Solarwinds Serv-u | 21/7/2026 | 24/7/2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments. | |
| Analizada | Alta (7.5) | 1.9% | ⚠ Explotación activa | Solarwinds Serv-u | 4/6/2026 | 22/7/2026 | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update | |
| Analizada | Alta (7.2) | 0.58% | — | Solarwinds Serv-u | 24/2/2026 | 17/6/2026 | An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently… | |
| Analizada | Alta (7.2) | 0.45% | — | Solarwinds Serv-u | 24/2/2026 | 17/6/2026 | A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under… | |
| Analizada | Alta (7.2) | 0.45% | — | Solarwinds Serv-u | 24/2/2026 | 17/6/2026 | A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under… | |
| Analizada | Alta (7.2) | 0.51% | — | Solarwinds Serv-u | 24/2/2026 | 17/6/2026 | A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative privileges to abuse. On Windows deployments,… | |
| Analizada | Crítica (9.1) | 1.1% | — | Solarwinds Serv-u | 18/11/2025 | 17/6/2026 | A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences in how paths and home… | |
| Analizada | Crítica (9.1) | 0.70% | — | Solarwinds Serv-u | 18/11/2025 | 17/6/2026 | A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged… | |
| Analizada | Crítica (9.1) | 0.89% | — | Solarwinds Serv-u | 18/11/2025 | 17/6/2026 | A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged… | |
| Analizada | Media (5.4) | 0.38% | — | Solarwinds Serv-u | 15/4/2025 | 17/6/2026 | SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low. | |
| Analizada | Media (4.1) | 0.89% | — | Solarwinds Serv-u | 16/10/2024 | 17/6/2026 | Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload. |