Critical SolarWinds Serv-U Vulnerabilities Allow Remote Code Execution as Root
ID: 033e5d76-21e4-5660-919d-10fa220046b1
STIX ID: report--033e5d76-21e4-5660-919d-10fa220046b1
Feed Name: Cyber Press
Threat Score
SolarWinds disclosed 15 Serv-U vulnerabilities (14 critical, CVSS 9.1) that predominantly consist of IDOR and privilege-escalation flaws enabling domain/group admins or authenticated users to escalate to system administrator and achieve remote code execution as root on Linux; Serv-U 2026.3 (released 21 July 2026) patches the issues and hardens related policies, and organizations—particularly Linux-based or internet-facing deployments—are urged to apply the update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
