CVE-2026-28321
- EPSS 0.4%
- Veröffentlicht 21.07.2026 15:39:46
- Zuletzt bearbeitet 24.07.2026 18:35:46
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact i...
CVE-2026-28317
- EPSS 0.34%
- Veröffentlicht 21.07.2026 15:39:30
- Zuletzt bearbeitet 24.07.2026 18:38:44
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
CVE-2026-28316
- EPSS 1.28%
- Veröffentlicht 21.07.2026 15:39:17
- Zuletzt bearbeitet 24.07.2026 18:40:25
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with...
CVE-2026-28315
- EPSS 0.28%
- Veröffentlicht 21.07.2026 15:39:04
- Zuletzt bearbeitet 24.07.2026 18:41:35
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.
CVE-2026-28314
- EPSS 0.45%
- Veröffentlicht 21.07.2026 15:38:39
- Zuletzt bearbeitet 24.07.2026 18:42:10
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
CVE-2026-28313
- EPSS 0.34%
- Veröffentlicht 21.07.2026 15:38:22
- Zuletzt bearbeitet 24.07.2026 18:43:36
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
CVE-2026-28312
- EPSS 0.4%
- Veröffentlicht 21.07.2026 15:37:45
- Zuletzt bearbeitet 24.07.2026 18:44:00
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
CVE-2026-28310
- EPSS 0.34%
- Veröffentlicht 21.07.2026 15:35:07
- Zuletzt bearbeitet 24.07.2026 18:44:22
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
CVE-2026-28309
- EPSS 0.34%
- Veröffentlicht 21.07.2026 15:34:52
- Zuletzt bearbeitet 24.07.2026 18:44:45
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
CVE-2026-28308
- EPSS 0.55%
- Veröffentlicht 21.07.2026 15:34:40
- Zuletzt bearbeitet 24.07.2026 18:45:04
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.