CVE-2019-12769: SolarWinds Serv-U Managed File Transfer

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.

Affected products

  • SolarWinds Serv-U Managed File Transfer: up to and including 15.1.5; version 15.1.6 only

Published 2020-03-18. Last modified 2026-06-17.