Vulnerabilities (CVE)

Filtered by vendor Solarwinds Subscribe
Filtered by product Serv-u
Total 40 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-28318 1 Solarwinds 1 Serv-u 2026-06-17 N/A 7.5 HIGH
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
CVE-2025-40549 1 Solarwinds 1 Serv-u 2026-06-17 N/A 9.1 CRITICAL
A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences in how paths and home directories are handled.
CVE-2025-40548 1 Solarwinds 1 Serv-u 2026-06-17 N/A 9.1 CRITICAL
A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
CVE-2025-40547 1 Solarwinds 1 Serv-u 2026-06-17 N/A 9.1 CRITICAL
A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
CVE-2025-40541 1 Solarwinds 1 Serv-u 2026-06-17 N/A 9.1 CRITICAL
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
CVE-2025-40540 1 Solarwinds 1 Serv-u 2026-06-17 N/A 9.1 CRITICAL
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
CVE-2025-40539 1 Solarwinds 1 Serv-u 2026-06-17 N/A 9.1 CRITICAL
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
CVE-2025-40538 1 Solarwinds 1 Serv-u 2026-06-17 N/A 9.1 CRITICAL
A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
CVE-2024-45714 1 Solarwinds 1 Serv-u 2026-06-17 N/A 4.8 MEDIUM
Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.
CVE-2024-45712 1 Solarwinds 1 Serv-u 2026-06-17 N/A 2.6 LOW
SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.
CVE-2024-45711 1 Solarwinds 1 Serv-u 2026-06-17 N/A 7.5 HIGH
SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when software environment variables are abused. Authentication is required for this vulnerability
CVE-2024-28995 1 Solarwinds 1 Serv-u 2026-06-17 N/A 8.6 HIGH
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
CVE-2024-28073 1 Solarwinds 1 Serv-u 2026-06-17 N/A 8.4 HIGH
SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.
CVE-2024-28072 1 Solarwinds 1 Serv-u 2026-06-17 N/A 5.7 MEDIUM
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
CVE-2023-40060 1 Solarwinds 1 Serv-u 2026-06-17 N/A 7.2 HIGH
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4.  SolarWinds found that the issue was not completely fixed in 15.4 Hotfix 1. 
CVE-2023-40053 1 Solarwinds 1 Serv-u 2026-06-17 N/A 5.0 MEDIUM
A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.
CVE-2023-35179 1 Solarwinds 1 Serv-u 2026-06-17 N/A 7.2 HIGH
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 
CVE-2023-23841 1 Solarwinds 1 Serv-u 2026-06-17 N/A 7.5 HIGH
SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.  Part of the URL of the request discloses sensitive data.
CVE-2022-38106 1 Solarwinds 1 Serv-u 2026-06-17 N/A 5.4 MEDIUM
This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.
CVE-2021-3154 1 Solarwinds 1 Serv-u 2026-06-17 5.0 MEDIUM 7.5 HIGH
An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.