Sunday, September 6, 2026

SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root

SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems.

This update significantly strengthens the managed file transfer (MFT) and FTP server platform against potential takeovers. While Windows instances are rated as having a lower impact, the wide range of issues addressed in this release makes upgrading essential for any file transfer infrastructure exposed to the internet.

SolarWinds Serv-U Update Fixes 15 CVEs

The release notes for version 2026.3 document 15 high-impact vulnerabilities in both the Serv-U MFT and Serv-U FTP Server. Many of these vulnerabilities stem from issues like broken access control and insecure direct object references (IDOR), which can lead to complete system compromise.

Several flaws enable authenticated domain or group administrators to escalate their privileges to that of a system administrator, allowing them to execute arbitrary code as root.

In this way, attackers can gain shell-level control over Unix-like systems. At the same time, Windows deployments generally result in elevated but somewhat limited permissions.

Importantly, multiple instances of IDOR can enable remote code execution as root if an attacker acquires a domain admin account with write access to the home directory, or if they exploit SMTP and account-handling processes for arbitrary account takeover.

When combined with broken access controls that permit domain admins to create new system administrator accounts or change user types, these flaws create reliable exploitation pathways for attackers to move from application-level access to complete server compromise.

In addition to addressing CVEs, Serv-U 2026.3 implements several security hardening measures aimed at reducing the risk of future code injection and web client abuse.

Content Security Policies have been strengthened, and new browser security headers, including Permissions-Policy and various cross-origin policies, have been implemented to limit what the web client can load and execute.

Multi-factor authentication support has been expanded to include Microsoft Active Directory and general LDAP users, closing gaps where only local and database accounts could enforce strong authentication.

SolarWinds has also resolved a stored cross-site scripting (XSS) vulnerability that previously allowed an attacker to hijack sessions or exfiltrate data from administrator accounts through maliciously crafted content stored within the application.

Enhancements in logging for failed uploads, better handling of stale file-share pages, and improved compatibility with clients (including fixes for rendering issues in Safari and Firefox) collectively improve operational security visibility and reduce the risk of undetected failures.

CVE IDTitleDescription (short)CVSSRequirement / Notes
CVE-2026-28302Serv-U IDORIDOR leading to privilege escalation and RCE as root; requires group administrator access; lower impact on Windows.9.1Group admin needed; impact lower on Windows.
CVE-2026-28304Serv-U RCERCE enabling arbitrary code execution remotely as root; lower impact on Windows.9.1Remote code execution as root.
CVE-2026-28305Serv-U IDORIDOR leading to RCE as root; needs domain admin with read/write access to home directory; lower impact on Windows.9.1Domain admin with home-dir access required.
CVE-2026-28306Serv-U privilege escalationDomain administrator can elevate to system administrator; lower impact on Windows.9.1Domain admin to system admin escalation.
CVE-2026-28307Serv-U privilege escalationDomain user group can be elevated into administrator group; lower impact on Windows.9.1Group-level escalation to admin.
CVE-2026-28308Serv-U IDORIDOR leading to RCE; domain administrator access required; lower impact on Windows.9.1Domain admin prerequisite.
CVE-2026-28309Serv-U broken access controlDomain administrator can create system administrator accounts; lower impact on Windows.9.1Arbitrary system admin creation.
CVE-2026-28310Serv-U privilege escalationDomain administrator can escalate their user type to system administrator; lower impact on Windows.9.1Direct type change to system admin.
CVE-2026-28311Serv-U RCEDomain administrator can modify application behavior leading to RCE; lower impact on Windows.9.1Behavior modification to reach RCE.
CVE-2026-28312Serv-U privilege escalationGroup’s access elevated to system administrator, enabling code execution as root; lower impact on Windows.9.1Group-to-system admin, root code execution.
CVE-2026-28313Serv-U IDORIDOR enabling SMTP hijacking and arbitrary account takeover; lower impact on Windows.9.1SMTP hijack → account takeover.
CVE-2026-28314Serv-U IDORIDOR leading to account takeover; user authentication required; lower impact on Windows.9.1Authenticated user takeover path.
CVE-2026-28315Serv-U stored XSSStored XSS enabling session hijacking or information disclosure from admin accounts.6.2Medium; admin-focused XSS risk.
CVE-2026-28316Serv-U IDORIDOR allowing privilege escalation to system administrator and root command execution; domain admin needed; lower impact on Windows.9.1Domain admin to root via system admin.
CVE-2026-28317Serv-U IDORIDOR leading to privilege escalation; domain administrator access required; lower impact on Windows.9.1Additional domain admin escalation path.
CVE-2026-28321Serv-U broken access controlBroken access control enabling arbitrary file read/write, then privilege escalation and root code execution; domain admin required; lower impact on Windows.9.1File abuse → root RCE via domain admin.

Organizations still running Serv-U 15.5.1 or earlier are in a precarious position, as the End-of-Engineering and End-of-Life timelines mean these older versions will soon stop receiving security updates.

Given the history of Serv-U RCE vulnerabilities being included in CISA’s Known Exploited Vulnerabilities catalog, it is wise to treat these 9.1 CVSS flaws as high-likelihood targets for both opportunistic and targeted attacks.

Best practices for defenders include upgrading all Serv-U MFT and FTP instances to version 2026.3 immediately, restricting administrative access, enforcing multi-factor authentication for all supported identity stores, and reviewing logs for any unusual admin creation or configuration changes that may indicate attempts at exploitation.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded...

Related Articles

Recent News