CVE-2018-16792: SolarWinds Sftp/scp Server
Critical severity, CVSS 9.1. EPSS: 1.4% chance of exploitation in the next 30 days.
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
Affected products
- SolarWinds Sftp/scp Server: up to and including 2018-09-10
Published 2018-12-05. Last modified 2026-06-17.