SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-28321

CRITICAL · CVSS 9.1 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

SolarWinds Serv-U on Windows is vulnerable due to a broken access control issue that permits arbitrary file read and write operations, potentially enabling privilege escalation and remote code execution. While the impact is reduced in Windows environments, domain administrators should prioritize addressing this critical vulnerability to mitigate risks associated with unauthorized access and system compromise.

CVE
CVE-2026-28321
Severity
CRITICAL
CVSS
9.1
EPSS
0.41%
Windows

Original NVD Description

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.

Related CVEs

Other vulnerabilities affecting the same vendor(s)