SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-28315

MEDIUM · CVSS 6.2 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

SolarWinds Serv-U is vulnerable to a stored cross-site scripting flaw that could allow attackers to hijack sessions or disclose sensitive information from administrator accounts. Organizations using this software should prioritize remediation efforts to mitigate potential unauthorized access and data breaches. Given the medium severity rating, it is essential for users with administrative privileges to assess their exposure and implement necessary security measures promptly.

CVE
CVE-2026-28315
Severity
MEDIUM
CVSS
6.2
EPSS
0.28%

Original NVD Description

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.

Related CVEs

Other vulnerabilities affecting the same vendor(s)