SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability (CVE-2026-28315)

Summary

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.


Affected Products

SolarWinds Serv-U 15.5.4 HF1 and below


Fixed Software Release

SolarWinds Serv-U 2026.3

Advisory Details
Severity

6.2 Medium

Advisory ID
First Published

07/21/2026

Fixed Version
CVSS Score
Download PDF
Send an Email