Serv U
Vendor:
First CVE: May 16, 2018 · Active for 8 years
55
Total CVEs
More Total CVEs than 98% of tracked products
6.9
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
7.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Serv U over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2018
8 years ago
Most Recent CVE
Jul 21, 2026
6 days ago
CVE Severity & Scoring
Serv U55 CVEs
29%
29%
42%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.8%)
Network54 (98.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low55 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None45 (81.8%)
Unknown0 (0.0%)
Required10 (18.2%)
Privileges Required
Low13 (23.6%)
High27 (49.1%)
None15 (27.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-28995HIGH SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. | Jun 6, 2024 | 7.5 | 98 | YES | YES |
CVE-2021-35211CRITICAL Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may b | Jul 14, 2021 | 10.0 | 95 | YES | NO |
CVE-2026-28318HIGH SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provi | Jun 4, 2026 | 7.5 | 81 | YES | NO |
CVE-2021-35247MEDIUM Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional valida | Jan 10, 2022 | 5.3 | 57 | YES | NO |
CVE-2026-28317CRITICAL SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. Th | Jul 21, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-28307CRITICAL SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows dep | Jul 21, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-28302CRITICAL SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requir | Jul 21, 2026 | 9.1 | 40 | NO | NO |
CVE-2021-35250HIGH A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been | Apr 25, 2022 | 7.5 | 40 | NO | YES |
CVE-2026-28321CRITICAL SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute cod | Jul 21, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-28316CRITICAL SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execut | Jul 21, 2026 | 9.1 | 39 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (55 CVEs).
CISA KEV
4 CVEs
7.3% of CVEs· 98th percentile
Metasploit
1 CVE
1.8% of CVEs· 97th percentile
Nuclei
2 CVEs
3.6% of CVEs· 97th percentile
ExploitDB
1 CVE
1.8% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (55 CVEs).
Media Mentions
Signals from CVEs in this product scope (55 CVEs).
Top CNAs Publishing CVEs For Serv U
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 15.5.4 | 1 | 7.5 | 8.3% | 1 | 0 |
| 15.4.2 | 2 | 6.6 | 66.6% | 1 | 1 |
| 15.4.0 | 3 | 6.1 | 0.9% | 0 | 0 |
| 15.3.1 | 1 | 5.4 | 0.7% | 0 | 0 |
| 15.3.0 | 1 | 5.4 | 0.7% | 0 | 0 |
| 15.3 | 1 | 7.5 | 14.7% | 0 | 1 |
| 15.2.5 | 1 | 6.8 | 1.2% | 0 | 0 |
| 15.2.4 | 1 | 6.8 | 1.2% | 0 | 0 |
| 15.2.3 | 1 | 10.0 | 91.2% | 1 | 0 |
| 15.2.2 | 1 | 7.1 | 0.5% | 0 | 0 |