
Critical SolarWinds Serv-U Vulnerabilities Allow Remote Code Execution as Root
SolarWinds has disclosed 15 vulnerabilities in its Serv-U managed file transfer software, with 14 rated Critical (CVSS 9.1) and capable of chaining privilege escalation into full remote code execution as root on Linux deployments. The flaws were patched in Serv-U 2026.3, released July 21, 2026, following coordinated disclosure through the Intigriti Bug Bounty Program. The […]
The post Critical SolarWinds Serv-U Vulnerabilities Allow Remote Code Execution as Root appeared first on Cyber Security News.