CVE-2024-28995: SolarWinds Serv-U Path Traversal Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2024-07-17. EPSS: 99.6% chance of exploitation in the next 30 days.

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Affected products

  • SolarWinds Serv-U: before 15.4.2 (fixed in 15.4.2); version 15.4.2 only

Published 2024-06-06. Last modified 2026-06-17.