Skip to content
COOEY

FAIL › dossier

Serv-U

PRODUCT

· dossier confidence 80%

Serv-U is a remote administration software product with a history of critical vulnerabilities including a 2021 RCE0day actively exploited in the wild.

PROFILE
CategorySoftware ProductWhat they doServ-U is a remote administration and file transfer software product used for managing servers and file systems.
SECURITY POSTURE

Track record includes multiple critical and high-severity vulnerabilities, including a 2021 critical RCE0day that was actively exploited in the wild.

Notable failures
  • 2021-11-03 CVE-2021-35211 critical RCE0day exploited in wild
  • 2024-07-17 CVE-2024-28995 high path traversal vulnerability
  • 2022-01-21 CVE-2021-35247 high improper input validation
  • 2026-06-05 CVE-2026-28318 high unauthenticated service crashes
Patterns: Repeated critical and high severity vulnerabilities in remote administration software; Unpatched edge-device RCEs
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-35211 critical SolarWinds Serv-U contained a memory escape vulnerability enabling remote code execution and was actively exploited in the wild, linked to ransomware activity.
2022-01-21 CVE-2021-35247 high SolarWinds Serv-U versions 15.2.5 and earlier suffer from improper input validation allowing attackers to send unsanitized queries.
2024-07-17 CVE-2024-28995 high SolarWinds Serv-U allows remote attackers to read sensitive files via a path traversal vulnerability.
2026-06-05 CVE-2026-28318 high SolarWinds Serv-U allows unauthenticated service crashes via crafted POST requests with a specific Content-Encoding header.
Open questions: Company ownership and size · HQ location · Website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-31 03:57:05.062092+00:00