SolarWinds Serv-U 2026.3 Patches 16 Vulnerabilities (CVE-2026-28302 to CVE-2026-28321) Including Root RCE, IDOR-Chained Privilege Escalation, and Broken Access Control — Threadlinqs Intelligence
As of 2026-07-22, SolarWinds Serv-U 2026.3 Patches 16 Vulnerabilities (CVE-2026-28302 to CVE-2026-28321) Including Root RCE, IDOR-Chained Privilege Escalation, and Broken Access Control is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1625 · Severity: CRITICAL · CVSS: 9.1 · Status: ACTIVE · Category: VULNERABILITY
SolarWinds released Serv-U 2026.3 on 2026-07-21, fixing 16 vulnerabilities in the managed file-transfer product, 15 of which are CVSS 9.1 CRITICAL. Most chain insecure direct object references (IDOR)
On 2026-07-21, SolarWinds shipped Serv-U 2026.3, a security-focused release addressing 16 vulnerabilities in its Serv-U managed file transfer server and gateway software. Fifteen of the sixteen flaws (CVE-2026-28302, 28304-28317, 28321) carry a CVSS v3.1 base score of 9.1 (Critical); the sixteenth, CVE-2026-28315, is a stored cross-site scripting flaw rated 6.2 (Medium). Fifteen of the sixteen CVEs were responsibly disclosed through the Intigriti bug bounty program; CVE-2026-28315 was reported separately.
The critical cluster is dominated by insecure direct object reference (IDOR) and broken access control weaknesses (CVE-2026-28302, 28305, 28308, 28313, 28314, 28316, 28317, 28321) combined with privilege-escalation logic flaws (CVE-2026-28306, 28307, 28309, 28310, 28312) and two flaws SolarWinds classifies directly as remote code execution (CVE-2026-28304, 28311). Exploitation of the most severe chains requires an attacker to already hold some level of authenticated access — domain administrator, group administrator, or an authenticated domain-user account — as a starting foothold. From that position, the IDOR and access-control flaws let an attacker bypass object-level authorization checks to escalate a domain-admin or group-admin account to full system-administrator, then abuse system-administrator functionality (e.g., account/profile configuration, file management APIs) to execute arbitrary commands as root on Linux-based Serv-U deployments. CVE-2026-28309 specifically allows a domain administrator to create unauthorized system-administrator accounts, and CVE-2026-28321 (broken access control) permits arbitrary file read and write, which is itself sufficient for code execution via web-writable paths or configuration tampering. CVE-2026-28313 chains an IDOR into SMTP-relay hijacking, enabling account takeover via intercepted or forged outbound mail (e.g., password-reset interception). CVE-2026-28314 and CVE-2026-28316/28317 enable authenticated-user account takeover and further privilege escalation through insecure object references. CVE-2026-28315, the lone non-critical finding, is a stored XSS that can be used to hijack administrator sessions or exfiltrate admin-panel information.
All versions of Serv-U prior to 2026.3 are affected; 2026.3 (released 2026-07-21) is the fixed version. As of publication, no vendor advisory, CISA KEV entry, or public researcher writeup documents active exploitation or a public proof-of-concept for the 2026.3 batch, distinguishing it from the separate, actively-exploited CVE-2026-28318 (unauthenticated denial-of-service via crafted `Content-Encoding: deflate` POST requests) that SolarWinds patched in Serv-U 15.5.4 Hotfix 1 on 2026-06-03 and that CISA added to its Known Exploited Vulnerabilities catalog on 2026-06-05 with a federal remediation deadline of 2026-06-19. Shodan-indexed exposure for Serv-U at the time of the CVE-2026-28318 KEV addition was approximately 12,000+ internet-facing instances, indicating a comparably large exposed attack surface for any of the newly disclosed authenticated-privilege-escalation chains once a foothold (e.g., stolen domain-admin credentials, a prior IDOR, or a phished domain-user account) is obtained. SolarWinds Serv-U has a documented recurring pattern of privilege-escalation vulnerabilities, with a structurally similar flaw (CVE-2025-40538) patched in version 15.5.4.
Defenders should treat the 2026.3 update as urgent given: (1) the sheer count of CVSS 9.1 findings in a single release, (2) the demonstrated real-world targeting of Serv-U (CVE-2026-28318 KEV entry, active exploitation as of June 2026), (3) the low bar for the escalation chains once any authenticated foothold exists (a single compromised domain-user or domain-admin credential is a viable starting point), and (4) the root-level code-execution outcome on Linux hosts, which typically run Serv-U as a high-value file-transfer chokepoint holding sensitive customer/partner data.
Weaknesses (CWE)
CWE-639, CWE-284, CWE-269, CWE-79, CWE-306, CWE-434
Target sectors: technology, managed-file-transfer-users, enterprise-it, government administration, finance, health
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-28302, CVE-2026-28304, CVE-2026-28305, CVE-2026-28306, CVE-2026-28307, CVE-2026-28308, CVE-2026-28309, CVE-2026-28310, CVE-2026-28311, CVE-2026-28312, T1190, T1133, T1068, T1078, T1548, T1136, T1098, T1505, T1222, T1078