FAIL › dossier
Serv-U
PRODUCT· dossier confidence 80%
Serv-U is a remote administration software product with a history of critical vulnerabilities including a 2021 RCE0day actively exploited in the wild.
PROFILE
CategorySoftware ProductWhat they doServ-U is a remote administration and file transfer software product used for managing servers and file systems.
SECURITY POSTURE
Track record includes multiple critical and high-severity vulnerabilities, including a 2021 critical RCE0day that was actively exploited in the wild.
Notable failures
- 2021-11-03 CVE-2021-35211 critical RCE0day exploited in wild
- 2024-07-17 CVE-2024-28995 high path traversal vulnerability
- 2022-01-21 CVE-2021-35247 high improper input validation
- 2026-06-05 CVE-2026-28318 high unauthenticated service crashes
Patterns: Repeated critical and high severity vulnerabilities in remote administration software; Unpatched edge-device RCEs
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2021-35211 | critical | SolarWinds Serv-U contained a memory escape vulnerability enabling remote code execution and was actively exploited in the wild, linked to ransomware activity. |
| 2022-01-21 | CVE-2021-35247 | high | SolarWinds Serv-U versions 15.2.5 and earlier suffer from improper input validation allowing attackers to send unsanitized queries. |
| 2024-07-17 | CVE-2024-28995 | high | SolarWinds Serv-U allows remote attackers to read sensitive files via a path traversal vulnerability. |
| 2026-06-05 | CVE-2026-28318 | high | SolarWinds Serv-U allows unauthenticated service crashes via crafted POST requests with a specific Content-Encoding header. |
Open questions: Company ownership and size · HQ location · Website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-31 03:57:05.062092+00:00