Known vulnerabilities in Serv-U FTP Server

Vendor: SolarWinds
Software CPE: cpe:2.3:a:solarwinds:serv-u_ftp_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 63
Public exploits: 8
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Serv-U FTP Server Serv-U FTP Server is affected by 63 known vulnerabilities: 2 critical, 9 high, 14 medium, 38 low Critical High Medium Low

Vulnerabilities (63)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139626 - Improper Access Control
CVE-2026-28309
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139625 - Improper Access Control
CVE-2026-28310
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139624 - Authorization Bypass Through User-Controlled Key
CVE-2026-28313
CWE-639 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139623 - Authorization Bypass Through User-Controlled Key
CVE-2026-28314
CWE-639 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139622 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-28315
CWE-79 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139621 - Improper Access Control
CVE-2026-28307
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139620 - Improper Access Control
CVE-2026-28321
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139683 - Authorization Bypass Through User-Controlled Key
CVE-2026-28302
CWE-639 Medium
No
No
2026.3 21.07.2026 SB20260727223
#VU139684 - Improper Access Control
CVE-2026-28304
CWE-284 High
No
No
2026.3 21.07.2026 SB20260727223
#VU139685 - Authorization Bypass Through User-Controlled Key
CVE-2026-28305
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139686 - Improper Privilege Management
CVE-2026-28306
CWE-269 Medium
No
No
2026.3 21.07.2026 SB20260727223
#VU139687 - Authorization Bypass Through User-Controlled Key
CVE-2026-28308
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139688 - Improper Access Control
CVE-2026-28311
CWE-284 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139689 - Improper Privilege Management
CVE-2026-28312
CWE-269 Medium
No
No
2026.3 21.07.2026 SB20260727223
#VU139690 - Authorization Bypass Through User-Controlled Key
CVE-2026-28316
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139691 - Authorization Bypass Through User-Controlled Key
CVE-2026-28317
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU134153 - Improper Handling of Exceptional Conditions
CVE-2026-28318
CWE-755 High
No
Exploited
15.5.4 Hotfix 1 09.06.2026 SB2026060972
#VU123150 - Type confusion
CVE-2025-40539
CWE-843 High
No
No
15.5.4 24.02.2026 SB2026022404
#VU123147 - Type confusion
CVE-2025-40540
CWE-843 High
No
No
15.5.4 24.02.2026 SB2026022404
#VU123145 - Improper Access Control
CVE-2025-40538
CWE-284 High
No
No
15.5.4 24.02.2026 SB2026022404


Showing elements 1 - 20 out of 63