CVE-2026-28304
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
21/07/2026
Last modified:
24/07/2026
Description
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* | 2026.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



