Code Defence Cyber security

Mass automated exploitation targets SolarWinds Serv-U Managed File Transfer directory traversal flaw CVE-2026-28914

Internet threat monitoring arrays report widespread automated scanning and exploitation targeting a directory traversal weakness in a widely deployed managed file transfer solution. Adversaries leverage public proof of concept scripts to read configuration files and extract administrative service credentials.

The vulnerability, tracked as CVE-2026-28914, impacts SolarWinds Serv-U File Server and Serv-U MFT releases prior to version 15.5.2. The security defect resides within URI path normalization subroutines handling web client requests. Unauthenticated remote actors transmit crafted path traversal sequences to bypass root directory restrictions, reading arbitrary system files including configuration catalogs containing encrypted administrative account credentials and internal secret keys. Threat actors leverage extracted keys to forge administrative sessions and execute secondary payloads.

Compromising managed file transfer infrastructure creates severe enterprise data privacy and credential theft risks. Because MFT servers process automated data transfers containing sensitive corporate files, financial records, and user credentials, an unauthenticated administrative compromise enables threat actors to exfiltrate critical datasets and deploy ransomware.

– Force immediate software maintenance upgrades across all SolarWinds Serv-U installations to release version 15.5.2 or higher.

– Inspect web server access logs for anomalous GET request URIs containing path traversal sequences or unverified file access calls.

– Rotate administrative passwords, service account credentials, and encryption keys stored within Serv-U configuration settings.

– Restrict public internet visibility of managed file transfer web portals using network access control lists.

Managed file transfer defense depends on rigid URI path normalization and prompt security patch deployment to ensure enterprise file exchange gateways remain completely protected from unauthenticated path traversal exploits. #CodeDefence #SolarWinds #ServU #MFT #DirectoryTraversal #AppSec #PatchManagement #CredentialTheft #DataSecurity
/

Scroll to Top