SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-28313

CRITICAL · CVSS 9.1 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

SolarWinds Serv-U on Windows is vulnerable to an insecure direct object reference (IDOR) flaw, which can be exploited to hijack SMTP sessions and potentially allow for arbitrary account takeover. While the impact is comparatively lower in Windows environments, organizations using this software should prioritize patching to mitigate the risk of unauthorized access. Security teams should assess their exposure and implement necessary updates promptly.

CVE
CVE-2026-28313
Severity
CRITICAL
CVSS
9.1
EPSS
0.34%
Windows

Original NVD Description

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.

Related CVEs

Other vulnerabilities affecting the same vendor(s)