Tag
critical
advisory
SolarWinds Serv-U Privilege Escalation Vulnerability (CVE-2026-28310)
1 TTP 1 CVE 2 IOCsCVE-2026-28310 describes a critical privilege escalation vulnerability (CVSS 9.1) affecting SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing a domain administrator to elevate their user type to that of a system administrator, with lower impact noted in Windows deployments.
Serv-U 15.5.4 HF1 and below
privilege-escalation
server-software
vulnerability
1t
1c
2i
critical
advisory
Remote Code Execution Vulnerability in SolarWinds Serv-U (CVE-2026-28304)
5 TTPs 8 CVEs 3 IOCsA critical remote code execution vulnerability (CVE-2026-28304) has been identified in SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing an attacker with high privileges to execute arbitrary code remotely as root, posing a severe risk to affected systems, though with lower impact on Windows deployments.
Serv-U +1
remote-code-execution
privilege-escalation
vulnerability-exploitation
vulnerability
cve
improper-access-control
server
software-update
+5
5t
8c
3i