Known vulnerabilities in Serv-U FTP Server 15.3 HF 1

Vendor: SolarWinds
Version: 15.3 HF 1
Software CPE: cpe:2.3:a:solarwinds:serv-u_ftp_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 33
Public exploits: 2
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Serv-U FTP Server version 15.3 HF 1 Serv-U FTP Server 15.3 HF 1 is affected by 33 vulnerabilities: 1 critical, 2 high, 6 medium, 24 low Critical High Medium Low

Vulnerabilities (33)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139626 - Improper Access Control
CVE-2026-28309
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139625 - Improper Access Control
CVE-2026-28310
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139624 - Authorization Bypass Through User-Controlled Key
CVE-2026-28313
CWE-639 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139623 - Authorization Bypass Through User-Controlled Key
CVE-2026-28314
CWE-639 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139622 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-28315
CWE-79 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139621 - Improper Access Control
CVE-2026-28307
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139620 - Improper Access Control
CVE-2026-28321
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139683 - Authorization Bypass Through User-Controlled Key
CVE-2026-28302
CWE-639 Medium
No
No
2026.3 21.07.2026 SB20260727223
#VU139684 - Improper Access Control
CVE-2026-28304
CWE-284 High
No
No
2026.3 21.07.2026 SB20260727223
#VU139685 - Authorization Bypass Through User-Controlled Key
CVE-2026-28305
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139686 - Improper Privilege Management
CVE-2026-28306
CWE-269 Medium
No
No
2026.3 21.07.2026 SB20260727223
#VU139687 - Authorization Bypass Through User-Controlled Key
CVE-2026-28308
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139688 - Improper Access Control
CVE-2026-28311
CWE-284 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139689 - Improper Privilege Management
CVE-2026-28312
CWE-269 Medium
No
No
2026.3 21.07.2026 SB20260727223
#VU139690 - Authorization Bypass Through User-Controlled Key
CVE-2026-28316
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139691 - Authorization Bypass Through User-Controlled Key
CVE-2026-28317
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU134153 - Improper Handling of Exceptional Conditions
CVE-2026-28318
CWE-755 High
No
Exploited
15.5.4 Hotfix 1 09.06.2026 SB2026060972
#VU122149 - Protection Mechanism Failure
CVE-2025-40549
CWE-693 Low
No
No
15.5.3 30.01.2026 SB2026013033
#VU122148 - Permissions, Privileges, and Access Controls
CVE-2025-40547
CWE-264 Low
No
No
15.5.3 30.01.2026 SB2026013033
#VU122147 - Improper Access Control
CVE-2025-40548
CWE-284 Low
No
No
15.5.3 30.01.2026 SB2026013033


Showing elements 1 - 20 out of 33