📦

serv-u

Vendor: rhinosoft

Actively Exploited 4 CISA KEV List
PoC / Exploits 8 Code Available
Total RCEs 3 Remote Access
Total CVEs 226 Total Indexed
Avg. EPSS 5.25% Exploit Prob.
Latest CVE CVE-2026-28321 Jul 21

Security Vulnerability Index

Page 6 / 23
6.1 CVSS

SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194.

EPSS: 1.50%
7.5 CVSS

SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.

EPSS: 1.52%
6.1 CVSS

SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421.

EPSS: 1.50%
6.5 CVSS

A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.

EPSS: 1.70%
7.3 CVSS

SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session.

EPSS: 1.06%
10.0 CVSS
CVE-2009-4873
Exploit Found

Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie.

EPSS: 20.55%
7.5 CVSS
CVE-2000-1033
Exploit Found

Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users.

EPSS: 7.56%
5.0 CVSS

The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.

EPSS: 2.08%