Threat monitoring arrays report widespread automated scanning and exploitation targeting a directory traversal vulnerability in a widely deployed managed file transfer server. Adversaries leverage public proof of concept scripts to extract configuration files and harvest cleartext credentials.
The vulnerability, tracked as CVE-2026-28914, affects SolarWinds Serv-U File Server and Serv-U MFT versions prior to 15.5.2. The bug stems from improper URI path normalization within web client interface handlers. An unauthenticated remote attacker can construct path traversal sequences to read arbitrary files outside the web root, including server configuration files containing encrypted admin credentials and local system secret keys. Threat actors exploit the retrieved keys to forge administrative sessions and gain arbitrary code execution rights.
Subverting managed file transfer infrastructure exposes sensitive corporate data vaults. Because MFT servers handle automated file exchanges containing financial records, intellectual property, and customer data, an administrative takeover permits threat actors to exfiltrate critical datasets and deploy secondary extortion payloads.
– Upgrade SolarWinds Serv-U installations immediately to patched version 15.5.2 or higher.
– Inspect web server access logs for anomalous GET requests containing path traversal character sequences.
– Rotate all administrative passwords and service account keys configured within Serv-U deployment settings.
– Restrict public web access to file transfer management interfaces using network access control lists.
Managed file transfer security relies on rigid path normalization and prompt patch deployment to ensure corporate file gateways remain protected from unauthenticated directory traversal exploits. #CodeDefence #SolarWinds #ServU #DirectoryTraversal #MFT #AppSec #PatchManagement #DataTheft
/
