High severity8.6CISA KEVNVD Advisory· Published Jun 6, 2024· Updated Jun 17, 2026
CVE-2024-28995
CVE-2024-28995
Description
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*range: <15.4.2
- cpe:2.3:a:solarwinds:serv-u:15.4.2:-:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:serv-u:15.4.2:hotfix1:*:*:*:*:*:*
- (no CPE)
- SolarWinds/SolarWinds Serv-Uv5Range: 15.4.2 HF 1 and previous versions
Patches
Vulnerability mechanics
References
2- www.solarwinds.com/trust-center/security-advisories/CVE-2024-28995nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
2- CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)Help Net Security · Jun 8, 2026
- CISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · Jun 5, 2026