Description
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv‑U is vulnerable to a remote code execution flaw that can allow an attacker to run arbitrary code with root privileges when the vulnerability is exploited. The weakness stems from improper access control (CWE‑284). In Windows deployments the impact is lower, but on Unix‑based systems the attacker could gain full system compromise.

Affected Systems

All affected installations of SolarWinds Serv‑U prior to the release of version 2026.3. The vendor specifically advises upgrading to Serv‑U 2026.3 to address the flaw. No precise affected version range was disclosed, so any instance running a pre‑2026.3 build should be considered vulnerable.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate severity overall, but the nature of the flaw—remote code execution—yields a high potential impact. The EPSS score of less than 1 % suggests low exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is remote network access to the Serv‑U service, with exploitation through normal client connections, assuming sufficient privileges are not enforced.

Generated by OpenCVE AI on August 1, 2026 at 06:56 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers to upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade Serv‑U to version 2026.3 as soon as practicable to apply the vendor fix.
  • Restrict inbound network traffic to the Serv‑U service by configuring firewalls or access control lists to limit exposure to trusted hosts.
  • Enforce strong authentication and least‑privilege access for all Serv‑U user accounts, ensuring that only authorized users can connect to privileged functions.
  • Monitor Serv‑U logs for anomalous activity and review connection patterns for signs of attempted exploitation.

Generated by OpenCVE AI on August 1, 2026 at 06:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Remote Code Execution Vulnerability
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:37.779Z

Reserved: 2026-02-26T14:15:09.403Z

Link: CVE-2026-28304

cve-icon Vulnrichment

Updated: 2026-07-21T18:30:57.659Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:00:04Z

Weaknesses