14 takeover flaws in enterprise file transfer SolarWinds Serv-U: CVE-2026-28302 et al. β update now
SolarWinds Serv-U, used for enterprise file transfer, has 14 flaws rated 9.1 disclosed at once (CVE-2026-28302 et al.). An admin-privileged user can read/write files beyond limits and reach privileged code execution (server takeover), with larger impact on Linux/Unix. Affected: 15.5.4 HF1 and earlier; update to the latest hotfix.
Table of contents
SolarWinds Serv-U, used for enterprise file transfer, has 14 flaws rated 9.1 disclosed at once (CVE-2026-28302 et al.). An admin-privileged user can read/write files beyond limits and reach privileged code execution (server takeover), with larger impact on Linux/Unix. Affected: 15.5.4 HF1 and earlier; update to the latest hotfix.
SolarWinds Serv-U, a file-transfer server widely used by enterprises, has 14 flaws disclosed at once, each rated 9.1 (Critical). Led by CVE-2026-28302, the set lets a user who holds administrator privileges read and write files beyond their intended limits and, ultimately, run code on the server (takeover). The impact is described as larger on Linux/Unix builds.
Affected are all versions up to and including Serv-U 15.5.4 Hotfix 1 (HF1). The vendor, SolarWinds, has shipped a later hotfix that fixes them. Serv-U is a "hub" where sensitive transferred data collects, and the product just had a separate, actively exploited denial-of-service flaw (CVE-2026-28318). Below we walk through what happens and how to respond.
Key points (3 lines)
- Enterprise file-transfer product SolarWinds Serv-U has 14 flaws rated 9.1. An admin-privileged party can read/write files beyond their limits and reach server takeover (code execution).
- Exploitation requires a Serv-U admin (domain / group administrator) β not an anyone-with-no-login case, but a real threat via insiders, stolen admin accounts, or post-intrusion escalation. Impact is larger on Linux/Unix.
- Affected: 15.5.4 HF1 and earlier. Update to the latest hotfix per SolarWinds' advisory.
Who targets this, and why
The people who can exploit these 14 flaws are those who hold a Serv-U admin account (domain or group administrator), or who obtained one somehow. This is not a no-login, anyone-from-outside vulnerability. But for a malicious insider, an attacker who phished an admin's credentials, or one who broke in another way and wants to widen access, it is an ideal "next move."
Using this set, an attacker performs file reads and writes that should be off-limits by confusing which object is targeted (IDOR), and turns that into code execution on the server. IDOR (insecure direct object reference) is a flaw where an off-limits object is manipulated by swapping an identifier. SolarWinds describes the result as "native code execution with privileged (root/administrator) authority." On Linux/Unix in particular, the impact of that privilege is larger.
The scale of damage isn't small. A file-transfer server like Serv-U is a chokepoint through which contracts, personal data, and confidential files pass and are stored. A takeover can mean bulk exfiltration, tampering, and a foothold into the internal network. File-transfer products have been prime targets for large-scale data theft and extortion in the past β so even with an admin prerequisite, this is not something to sit on. That's why the update below should be done promptly.
What the 14 flaws have in common
All 14 disclosed together are the same family: "broken access control" or "IDOR" that lets someone read/write files beyond their intended scope and chain it into privileged code execution. All are rated 9.1 (Critical) and share the prerequisite of a Serv-U admin. The specific entry points (which feature or parameter is abused) differ, but they all lead to "file operations beyond the limit" and "server takeover."
| CVE | Class | Severity | Precondition |
|---|---|---|---|
| CVE-2026-28302 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28304 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28305 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28306 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28307 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28308 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28309 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28310 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28312 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28313 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28314 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28316 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28317 | Broken access control / IDOR β privileged code exec | 9.1 | Admin required |
| CVE-2026-28321 | Broken access control β arbitrary file read/write | 9.1 | Admin required |
This many at once likely reflects a shared weakness in how Serv-U handles privileges, surfacing feature by feature. The CVE numbers differ, but since any single one can lead to a privileged takeover, updating to the fixed release is the only reliable fix. Note the separately disclosed denial-of-service flaw CVE-2026-28318 is an unauthenticated, actively exploited issue of a different family (fixed in 15.5.4 HF1).
Affected scope (version / OS quick reference)
Whether you're affected comes down to the Serv-U version you run. Check it in the management console or the install details.
| Your version | Impact | Action |
|---|---|---|
| 15.5.4 HF1 or earlier | All 14 apply | Update to the latest hotfix |
| Fixed release (after HF1) | Already fixed | No action needed |
| Host OS | Severity of impact |
|---|---|
| Linux / Unix | Larger (privileged execution is pronounced) |
| Windows | Relatively smaller, but still needs the fix |
SolarWinds notes the impact is larger on Linux/Unix than on Windows. But the flaws exist on Windows too, so update regardless of OS. Internet-facing Serv-U instances in particular should be prioritized, since a compromised admin account would do the most damage there.
What to do right now
The fix is to update Serv-U to the latest hotfix (the fixed release after 15.5.4 HF1), following SolarWinds' security advisory. All 14 require admin privileges, so they're not a no-login, mass-scan case β but since any one can lead to a privileged takeover, closing them together is the sure move. The latest fixed release and release notes are on SolarWinds' security advisories (Trust Center).
If you can't update immediately, useful stopgaps are to audit your Serv-U admin accounts, trim unnecessary admin privileges, enforce strong (multi-factor) authentication, and restrict how the management console can be reached. Since abuse hinges on admin privileges, "limit who can even become an admin" curbs the damage. Also confirm you've already handled the unauthenticated denial-of-service flaw (CVE-2026-28318) (fixed in 15.5.4 HF1).
As of publication, there is no report of these 14 being used in real attacks and no listing on the U.S. CISA catalog of actively exploited vulnerabilities (KEV). Still, SolarWinds Serv-U just had a separate flaw exploited and KEV-listed, and it's a high-profile product. You can check how far attacks are spreading in our tracker of actively exploited vulnerabilities (Japanese).
FAQ
Q. Can anyone exploit it with no login?
No. All 14 require a Serv-U admin (domain / group administrator) to exploit. This isn't a no-login, anyone-from-outside case. But it's a real threat via insiders, stolen admin accounts, or post-intrusion escalation, so updating is necessary.
Q. How dangerous is it?
All 14 are rated 9.1 (Critical). An admin-privileged party can read/write files beyond their limits and reach privileged (root/administrator) code execution β i.e. server takeover. The impact is described as larger on Linux/Unix builds.
Q. Is this separate from the recent DoS flaw?
Yes. The earlier CVE-2026-28318 is an unauthenticated denial-of-service flaw that was actively exploited and fixed in 15.5.4 HF1. These 14 are access-control flaws that require admin privileges and are fixed in a release after HF1. Confirm you've handled both.
Q. Which version should I move to?
Affected is 15.5.4 HF1 and earlier. Update to the latest hotfix named in SolarWinds' security advisory (Trust Center). For the exact fixed version number, follow the advisory's wording.
Summary
SolarWinds Serv-U, used for enterprise file transfer, has 14 flaws rated 9.1 disclosed at once. Led by CVE-2026-28302, these access-control/IDOR flaws let an admin-privileged party read/write files beyond limits and reach privileged code execution (takeover). Exploitation needs admin privileges, so it's not a no-login mass-scan case β but it's a real threat via insiders, stolen admin accounts, or post-intrusion escalation, and impact is larger on Linux/Unix.
The fix is to update to the latest hotfix (the fixed release after 15.5.4 HF1) per SolarWinds' advisory. Also audit admin accounts, enforce MFA, and restrict console reachability. Serv-U is a chokepoint where confidential files collect, and it just had a separate flaw exploited. Since leaving even one open can lead to a privileged takeover, don't put the update off.
Sources
- βΈ NVD - CVE-2026-28302 (SolarWinds Serv-U broken access control / IDOR β privileged code exec) and the other CVEs above
- βΈ SolarWinds - Security advisories (Trust Center: latest hotfix and release notes)
- βΈ SolarWinds Serv-U product page
- βΈ Related: SolarWinds Serv-U denial-of-service flaw CVE-2026-28318 (this site)
- βΈ Related: tracker of actively exploited vulnerabilities, CISA KEV (Japanese, this site)

Makoto Horikawa
Backend Engineer / AWS / Django