SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems.
This update significantly strengthens the managed file transfer (MFT) and FTP server platform against potential takeovers. While Windows instances are rated as having a lower impact, the wide range of issues addressed in this release makes upgrading essential for any file transfer infrastructure exposed to the internet.
SolarWinds Serv-U Update Fixes 15 CVEs
The release notes for version 2026.3 document 15 high-impact vulnerabilities in both the Serv-U MFT and Serv-U FTP Server. Many of these vulnerabilities stem from issues like broken access control and insecure direct object references (IDOR), which can lead to complete system compromise.
Several flaws enable authenticated domain or group administrators to escalate their privileges to that of a system administrator, allowing them to execute arbitrary code as root.
In this way, attackers can gain shell-level control over Unix-like systems. At the same time, Windows deployments generally result in elevated but somewhat limited permissions.
Importantly, multiple instances of IDOR can enable remote code execution as root if an attacker acquires a domain admin account with write access to the home directory, or if they exploit SMTP and account-handling processes for arbitrary account takeover.
When combined with broken access controls that permit domain admins to create new system administrator accounts or change user types, these flaws create reliable exploitation pathways for attackers to move from application-level access to complete server compromise.
In addition to addressing CVEs, Serv-U 2026.3 implements several security hardening measures aimed at reducing the risk of future code injection and web client abuse.
Content Security Policies have been strengthened, and new browser security headers, including Permissions-Policy and various cross-origin policies, have been implemented to limit what the web client can load and execute.
Multi-factor authentication support has been expanded to include Microsoft Active Directory and general LDAP users, closing gaps where only local and database accounts could enforce strong authentication.
SolarWinds has also resolved a stored cross-site scripting (XSS) vulnerability that previously allowed an attacker to hijack sessions or exfiltrate data from administrator accounts through maliciously crafted content stored within the application.
Enhancements in logging for failed uploads, better handling of stale file-share pages, and improved compatibility with clients (including fixes for rendering issues in Safari and Firefox) collectively improve operational security visibility and reduce the risk of undetected failures.
| CVE ID | Title | Description (short) | CVSS | Requirement / Notes |
|---|---|---|---|---|
| CVE-2026-28302 | Serv-U IDOR | IDOR leading to privilege escalation and RCE as root; requires group administrator access; lower impact on Windows. | 9.1 | Group admin needed; impact lower on Windows. |
| CVE-2026-28304 | Serv-U RCE | RCE enabling arbitrary code execution remotely as root; lower impact on Windows. | 9.1 | Remote code execution as root. |
| CVE-2026-28305 | Serv-U IDOR | IDOR leading to RCE as root; needs domain admin with read/write access to home directory; lower impact on Windows. | 9.1 | Domain admin with home-dir access required. |
| CVE-2026-28306 | Serv-U privilege escalation | Domain administrator can elevate to system administrator; lower impact on Windows. | 9.1 | Domain admin to system admin escalation. |
| CVE-2026-28307 | Serv-U privilege escalation | Domain user group can be elevated into administrator group; lower impact on Windows. | 9.1 | Group-level escalation to admin. |
| CVE-2026-28308 | Serv-U IDOR | IDOR leading to RCE; domain administrator access required; lower impact on Windows. | 9.1 | Domain admin prerequisite. |
| CVE-2026-28309 | Serv-U broken access control | Domain administrator can create system administrator accounts; lower impact on Windows. | 9.1 | Arbitrary system admin creation. |
| CVE-2026-28310 | Serv-U privilege escalation | Domain administrator can escalate their user type to system administrator; lower impact on Windows. | 9.1 | Direct type change to system admin. |
| CVE-2026-28311 | Serv-U RCE | Domain administrator can modify application behavior leading to RCE; lower impact on Windows. | 9.1 | Behavior modification to reach RCE. |
| CVE-2026-28312 | Serv-U privilege escalation | Group’s access elevated to system administrator, enabling code execution as root; lower impact on Windows. | 9.1 | Group-to-system admin, root code execution. |
| CVE-2026-28313 | Serv-U IDOR | IDOR enabling SMTP hijacking and arbitrary account takeover; lower impact on Windows. | 9.1 | SMTP hijack → account takeover. |
| CVE-2026-28314 | Serv-U IDOR | IDOR leading to account takeover; user authentication required; lower impact on Windows. | 9.1 | Authenticated user takeover path. |
| CVE-2026-28315 | Serv-U stored XSS | Stored XSS enabling session hijacking or information disclosure from admin accounts. | 6.2 | Medium; admin-focused XSS risk. |
| CVE-2026-28316 | Serv-U IDOR | IDOR allowing privilege escalation to system administrator and root command execution; domain admin needed; lower impact on Windows. | 9.1 | Domain admin to root via system admin. |
| CVE-2026-28317 | Serv-U IDOR | IDOR leading to privilege escalation; domain administrator access required; lower impact on Windows. | 9.1 | Additional domain admin escalation path. |
| CVE-2026-28321 | Serv-U broken access control | Broken access control enabling arbitrary file read/write, then privilege escalation and root code execution; domain admin required; lower impact on Windows. | 9.1 | File abuse → root RCE via domain admin. |
Organizations still running Serv-U 15.5.1 or earlier are in a precarious position, as the End-of-Engineering and End-of-Life timelines mean these older versions will soon stop receiving security updates.
Given the history of Serv-U RCE vulnerabilities being included in CISA’s Known Exploited Vulnerabilities catalog, it is wise to treat these 9.1 CVSS flaws as high-likelihood targets for both opportunistic and targeted attacks.
Best practices for defenders include upgrading all Serv-U MFT and FTP instances to version 2026.3 immediately, restricting administrative access, enforcing multi-factor authentication for all supported identity stores, and reviewing logs for any unusual admin creation or configuration changes that may indicate attempts at exploitation.
ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.





