Known vulnerabilities in Serv-U FTP Server 15.5.4 Hotfix 1

Vendor: SolarWinds
Version: 15.5.4 Hotfix 1
Software CPE: cpe:2.3:a:solarwinds:serv-u_ftp_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 16
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Serv-U FTP Server version 15.5.4 Hotfix 1 Serv-U FTP Server 15.5.4 Hotfix 1 is affected by 16 vulnerabilities: 1 high, 3 medium, 12 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139626 - Improper Access Control
CVE-2026-28309
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139625 - Improper Access Control
CVE-2026-28310
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139624 - Authorization Bypass Through User-Controlled Key
CVE-2026-28313
CWE-639 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139623 - Authorization Bypass Through User-Controlled Key
CVE-2026-28314
CWE-639 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139622 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-28315
CWE-79 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139621 - Improper Access Control
CVE-2026-28307
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139620 - Improper Access Control
CVE-2026-28321
CWE-284 Low
No
No
2026.3 27.07.2026 SB20260727223
#VU139683 - Authorization Bypass Through User-Controlled Key
CVE-2026-28302
CWE-639 Medium
No
No
2026.3 21.07.2026 SB20260727223
#VU139684 - Improper Access Control
CVE-2026-28304
CWE-284 High
No
No
2026.3 21.07.2026 SB20260727223
#VU139685 - Authorization Bypass Through User-Controlled Key
CVE-2026-28305
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139686 - Improper Privilege Management
CVE-2026-28306
CWE-269 Medium
No
No
2026.3 21.07.2026 SB20260727223
#VU139687 - Authorization Bypass Through User-Controlled Key
CVE-2026-28308
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139688 - Improper Access Control
CVE-2026-28311
CWE-284 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139689 - Improper Privilege Management
CVE-2026-28312
CWE-269 Medium
No
No
2026.3 21.07.2026 SB20260727223
#VU139690 - Authorization Bypass Through User-Controlled Key
CVE-2026-28316
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223
#VU139691 - Authorization Bypass Through User-Controlled Key
CVE-2026-28317
CWE-639 Low
No
No
2026.3 21.07.2026 SB20260727223