[WID-SEC-2026-2467] SolarWinds Serv-U: Mehrere Schwachstellen CVSS Base Score 9.1 (kritisch) CVSS Temporal Score 7.9 (hoch) Remoteangriff ja Datum 21.07.2026 Stand 22.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges Windows Produktbeschreibung SolarWinds Serv-U ist eine FTP-Server Software. Produkte 21.07.2026 SolarWinds Serv-U <2026.3 Angriff Angriff Ein entfernter, hochprivilegierter Angreifer kann mehrere Schwachstellen in SolarWinds Serv-U ausnutzen, um beliebigen Code als Root auszuführen, Administratorrechte zu erlangen, Konten zu übernehmen, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple critical vulnerabilities in SolarWinds Serv-U FTP server software allow a remote, highly-privileged attacker to execute arbitrary code with root/admin rights, take over accounts, disclose sensitive information, or conduct cross-site scripting attacks. The CVSS Base Score is 9.1 (Critical). Affected systems are all versions prior to Serv-U 2026.3, for which a mitigation is available.