logo

SolarWinds Serv-U Vulnerability Under Active Attack - Patch Immediately

ID: 6dcfee35-cad8-578c-b79e-19be9c750cb0

STIX ID: report--6dcfee35-cad8-578c-b79e-19be9c750cb0

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-06-21

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

A high-severity directory traversal flaw (CVE-2024-28995, CVSS 8.6) affecting SolarWinds Serv-U (<=15.4.2 HF1) allows unauthenticated attackers to read arbitrary files on disk; public PoCs and active exploitation (including attempts to access /etc/passwd) have been observed, and SolarWinds released Serv-U 15.4.2 HF2 to remediate the issue—organizations should apply the update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.