PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-28307 SolarWinds CVE debrief

A critical vulnerability was found in SolarWinds Serv-U, which allows a domain user group to be elevated into an administrator group. This privilege escalation vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. The impact is lower in Windows deployments due to stricter access controls. The CVE record was published on 2026-07-21T16:17:08.443Z and was last modified on 2026-07-22T19:17:01.270Z. Administrators and users of SolarWinds Serv-U should be aware of this vulnerability and take necessary actions to mitigate it. The vulnerability is described as CWE-284, Improper Access Control.

Vendor
SolarWinds
Product
Serv-U
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Administrators and users of SolarWinds Serv-U should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing and applying vendor security advisories and patches, monitoring and restricting access to sensitive areas of the system, and implementing compensating controls to limit the impact of the vulnerability. Vulnerability management and security teams should prioritize this vulnerability due to its critical severity and potential impact on system security.

Technical summary

The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The weakness is described as CWE-284, Improper Access Control. The vulnerability allows a domain user group to be elevated into an administrator group, potentially leading to full system compromise. The impact is lower in Windows deployments due to stricter access controls. However, the CVE record and NVD entry do not provide detailed information on specific attack vectors or affected configurations.

Defensive priority

High

Recommended defensive actions

  • Review and apply the vendor's security advisories and patches
  • Monitor and restrict access to sensitive areas of the system
  • Implement compensating controls to limit the impact of the vulnerability
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The evidence for this vulnerability is based on the CVE record and the NVD detail. The vendor's security advisories and patches should be reviewed and applied. However, the scope of affected deployments and specific attack vectors are not detailed in the CVE record or NVD entry. Defenders should verify the presence of SolarWinds Serv-U in their environment and review system logs for potential exploitation attempts. Additional verification is required to confirm the full impact and affected configurations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-28307 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-28307

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-28307 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28307

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.