logo

Critical SolarWinds Serv-U Vulnerabilities Allow Remote Code Execution as Root

ID: 033e5d76-21e4-5660-919d-10fa220046b1

STIX ID: report--033e5d76-21e4-5660-919d-10fa220046b1

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Tamilselvan

...
...

SolarWinds disclosed 15 Serv-U vulnerabilities (14 critical, CVSS 9.1) that predominantly consist of IDOR and privilege-escalation flaws enabling domain/group admins or authenticated users to escalate to system administrator and achieve remote code execution as root on Linux; Serv-U 2026.3 (released 21 July 2026) patches the issues and hardens related policies, and organizations—particularly Linux-based or internet-facing deployments—are urged to apply the update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.