{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/serv-u--15.5.4-hf1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-28304"},{"cvss":9.1,"id":"CVE-2026-28309"},{"cvss":9.1,"id":"CVE-2026-28306"},{"cvss":9.1,"id":"CVE-2026-28307"},{"cvss":9.1,"id":"CVE-2026-28316"},{"cvss":9.1,"id":"CVE-2026-28312"},{"cvss":9.1,"id":"CVE-2026-28313"},{"cvss":9.1,"id":"CVE-2026-28317"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Serv-U (15.5.4 HF1 and below)","Serv-U (\u003c= 15.5.4 HF1)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","privilege-escalation","vulnerability-exploitation","vulnerability","cve","improper-access-control","server","software-update","idor","account-takeover","server-software","access-control","server-application"],"_cs_type":"advisory","_cs_vendors":["SolarWinds"],"content_html":"\u003cp\u003eA critical remote code execution (RCE) vulnerability, identified as CVE-2026-28304, affects SolarWinds Serv-U File Transfer Protocol (FTP) server versions 15.5.4 HF1 and below. This flaw enables an attacker with high privileges to achieve arbitrary code execution remotely as the root user. While the vulnerability's impact is noted to be lower in Windows deployments, it presents a significant risk for full system compromise on other operating systems where \u0026quot;root\u0026quot; is a more powerful user. Given the nature of Serv-U, often used for critical file transfers, successful exploitation could lead to extensive data exfiltration, system integrity breaches, and service disruption. Defenders must prioritize patching to mitigate this severe risk. The specifics of the exploit, such as which high privilege allows the RCE, are not detailed in the NVD entry.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains high-privilege credentials for a SolarWinds Serv-U instance or the underlying operating system.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts and sends a malicious request to the vulnerable Serv-U application.\u003c/li\u003e\n\u003cli\u003eThe Serv-U application, operating with elevated privileges, processes the malformed input.\u003c/li\u003e\n\u003cli\u003eCVE-2026-28304 is triggered, leading to a bypass of security controls and arbitrary code execution.\u003c/li\u003e\n\u003cli\u003eThe attacker's payload executes with root privileges on the host system running Serv-U.\u003c/li\u003e\n\u003cli\u003eWith root access, the attacker establishes persistence mechanisms, exfiltrates sensitive data, or disrupts critical services.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-28304 grants an attacker remote code execution capabilities with root privileges. This level of access allows for complete control over the compromised Serv-U server, leading to potential full system compromise, data exfiltration of sensitive files, installation of additional malware or backdoors, and denial-of-service. While the NVD advisory notes a lower impact on Windows deployments, the \u0026quot;as root\u0026quot; designation suggests particularly severe consequences for Linux or Unix-based Serv-U installations, where root access provides unrestricted system control. Organizations using Serv-U for mission-critical operations or storing sensitive data are at high risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update SolarWinds Serv-U to version 15.5.4 HF2 or later to patch CVE-2026-28304, as specified in the SolarWinds advisory references.\u003c/li\u003e\n\u003cli\u003eImplement strong authentication measures and principle of least privilege for Serv-U accounts to mitigate the prerequisite of high privilege credentials for exploitation.\u003c/li\u003e\n\u003cli\u003eMonitor Serv-U application logs and system-level process creation logs (e.g., Sysmon on Windows, Auditd on Linux) for unusual activity indicating potential exploitation attempts or post-exploitation behavior.\u003c/li\u003e\n\u003cli\u003eReview firewall rules to restrict network access to Serv-U instances to only necessary source IPs and ports, reducing the attack surface for remote exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T16:29:51Z","date_published":"2026-07-21T16:19:10Z","id":"https://feed.craftedsignal.io/briefs/2026-07-solarwinds-serv-u-rce/","summary":"A critical remote code execution vulnerability (CVE-2026-28304) has been identified in SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing an attacker with high privileges to execute arbitrary code remotely as root, posing a severe risk to affected systems, though with lower impact on Windows deployments.","title":"Remote Code Execution Vulnerability in SolarWinds Serv-U (CVE-2026-28304)","url":"https://feed.craftedsignal.io/briefs/2026-07-solarwinds-serv-u-rce/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-28302"},{"cvss":9.1,"id":"CVE-2026-28308"},{"cvss":9.1,"id":"CVE-2026-28305"},{"cvss":9.1,"id":"CVE-2026-28314"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Serv-U","Serv-U (\u003c= 15.5.4 HF1)","Serv-U \u003c= 15.5.4 HF1"],"_cs_severities":["critical"],"_cs_tags":["idor","privilege-escalation","rce","file-transfer","vulnerability","serv-u","solarwinds"],"_cs_type":"advisory","_cs_vendors":["SolarWinds"],"content_html":"\u003cp\u003eSolarWinds Serv-U is affected by CVE-2026-28302, an insecure direct object reference (IDOR) vulnerability, that allows authenticated group administrators to escalate privileges and achieve remote code execution (RCE) as root. This critical vulnerability, with a CVSS v3.1 base score of 9.1, impacts Serv-U versions 15.5.4 HF1 and below. While the vulnerability affects both Linux and Windows deployments, the potential impact is noted to be lower in Windows environments. Exploitation requires an attacker to first gain group administrator access to a Serv-U instance. Once exploited, it grants the attacker the highest level of system access, posing a significant risk to the integrity and confidentiality of the affected servers and potentially the broader network.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains valid group administrator credentials for a vulnerable SolarWinds Serv-U instance, potentially through phishing, brute-force, or prior compromise.\u003c/li\u003e\n\u003cli\u003eThe authenticated attacker identifies an insecure direct object reference flaw within Serv-U's application logic, typically by observing how the application handles requests involving unique identifiers for resources or functions.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious request, manipulating an object identifier (e.g., a file path, user ID, or configuration setting ID) to bypass access controls and target a resource or function outside their intended scope.\u003c/li\u003e\n\u003cli\u003eThis IDOR exploitation successfully escalates the attacker's privileges from group administrator to a higher-privileged user, such as a system administrator or even root.\u003c/li\u003e\n\u003cli\u003eLeveraging these newly acquired elevated privileges, the attacker can then execute arbitrary commands on the underlying operating system where Serv-U is running.\u003c/li\u003e\n\u003cli\u003eOn Linux systems, these commands are executed as the root user, providing full control over the server; on Windows, commands run with elevated system privileges.\u003c/li\u003e\n\u003cli\u003eThis remote code execution allows the attacker to install backdoors, exfiltrate sensitive data, or deploy additional malicious payloads.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-28302 leads to severe consequences, primarily privilege escalation to root or SYSTEM and full remote code execution on the compromised server. Given that Serv-U is often used for file transfer in critical infrastructure and enterprise environments, this vulnerability could allow attackers to gain deep access into targeted networks. Attackers could exfiltrate sensitive data, disrupt operations, deploy ransomware, or use the compromised server as a pivot point for further attacks. The critical CVSS score of 9.1 reflects the high confidentiality, integrity, and availability impact of this vulnerability, making immediate patching essential.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-28302 by upgrading SolarWinds Serv-U to a patched version (15.5.4 HF2 or newer) immediately, as detailed in the SolarWinds security advisory and release notes referenced in this brief.\u003c/li\u003e\n\u003cli\u003eImplement strong access controls and monitoring for the Serv-U application, including regular auditing of group administrator accounts.\u003c/li\u003e\n\u003cli\u003eReview network segmentation to limit the blast radius in case of Serv-U compromise, ensuring Serv-U instances are not directly exposed to the internet unless absolutely necessary.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T16:28:09Z","date_published":"2026-07-21T16:18:04Z","id":"https://feed.craftedsignal.io/briefs/2026-07-solarwinds-servu-idor/","summary":"A critical insecure direct object reference (IDOR) vulnerability, CVE-2026-28302, in SolarWinds Serv-U allows authenticated group administrators to achieve privilege escalation and remote code execution as root.","title":"SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability Allows Privilege Escalation and RCE","url":"https://feed.craftedsignal.io/briefs/2026-07-solarwinds-servu-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - Serv-U (\u003c= 15.5.4 HF1)","version":"https://jsonfeed.org/version/1.1"}