Vulnerabilities
Vulnerable Software
Security Vulnerabilities
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.005
Published
2026-07-21
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.005
Published
2026-07-21
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.003
Published
2026-07-21
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.003
Published
2026-07-21
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.005
Published
2026-07-21
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.003
Published
2026-07-21
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.003
Published
2026-07-21
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.006
Published
2026-07-21
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVSS Score
9.1
EPSS Score
0.002
Published
2026-07-21
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-07-21


Contact Us

Shodan ® - All rights reserved