📦

serv-u

Vendor: rhinosoft

Actively Exploited 4 CISA KEV List
PoC / Exploits 8 Code Available
Total RCEs 3 Remote Access
Total CVEs 226 Total Indexed
Avg. EPSS 5.25% Exploit Prob.
Latest CVE CVE-2026-28321 Jul 21

Security Vulnerability Index

Page 3 / 23
9.1 CVSS

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences in how paths and home directories are handled.

EPSS: 1.04%
9.1 CVSS

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

EPSS: 0.68%
9.1 CVSS
CVE-2025-40547
Exploit Found

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

EPSS: 0.87%
2.6 CVSS

SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.

EPSS: 0.35%
4.8 CVSS

Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.

EPSS: 0.84%
7.5 CVSS

SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when software environment variables are abused. Authentication is required for this vulnerability

EPSS: 6.29%
Critical Target
8.6 CVSS
CVE-2024-28995
Exploit Found

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

EPSS: 99.61%
5.7 CVSS

A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.

EPSS: 0.64%
8.4 CVSS

SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.

EPSS: 1.12%
5.0 CVSS

A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.

EPSS: 0.83%