{"api_version":"v1","generated_at":"2026-10-08T14:05:00+00:00","product":{"cve_count":36,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-solarwinds-serv-u-09259d515c6a","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Serv-U","next_cursor":null,"observations":[{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28321","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28321","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:48.019Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:39:46.561Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28317","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28317","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:47.253Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:39:30.473Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28316","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28316","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:46.373Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:39:17.464Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28315","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28315","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-21T17:44:05.421Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:39:04.982Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28314","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28314","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:45.575Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:38:39.779Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28313","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28313","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:44.594Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:38:22.855Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28312","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28312","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:43.714Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:37:45.518Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28310","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28310","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:42.875Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:35:07.899Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28309","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28309","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:41.996Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:34:52.384Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28308","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28308","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:41.194Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:34:40.127Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28307","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28307","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:40.379Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:34:26.779Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28306","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28306","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:39.494Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:34:09.400Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28305","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28305","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:38.634Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:33:55.983Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28304","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28304","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T03:55:37.779Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm","primary_source":"","published":"2026-07-21T15:32:04.741Z"},{"affected":"15.5.4 HF1 and below","affected_versions_present":true,"cve_id":"CVE-2026-28302","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28302","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-24T03:55:36.930Z","patch_url":"","primary_source":"","published":"2026-07-21T15:31:30.297Z"},{"affected":"Serv-U: 15.5.4 and previous versions","affected_versions_present":true,"cve_id":"CVE-2026-28318","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28318","fixed":"Upgrade to SolarWinds Serv-U 15.5.4 Hotfix 1. Use the mitigation steps until the upgrade is possible.","last_modified":"2026-06-06T03:55:57.072Z","patch_url":"https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28318","primary_source":"","published":"2026-06-04T14:05:58.218Z"},{"affected":"SolarWinds Serv-U 15.5.3 and prior versions","affected_versions_present":true,"cve_id":"CVE-2025-40541","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-40541","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-26T14:44:09.404Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4_release_notes.htm","primary_source":"","published":"2026-02-24T07:41:49.921Z"},{"affected":"SolarWinds Serv-U 15.5.3 and prior versions","affected_versions_present":true,"cve_id":"CVE-2025-40540","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-40540","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-26T14:44:09.561Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4_release_notes.htm","primary_source":"","published":"2026-02-24T07:41:17.517Z"},{"affected":"SolarWinds Serv-U 15.5.3 and prior versions","affected_versions_present":true,"cve_id":"CVE-2025-40539","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-40539","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-26T14:44:09.712Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4_release_notes.htm","primary_source":"","published":"2026-02-24T07:40:46.244Z"},{"affected":"SolarWinds Serv-U 15.5.3 and prior versions","affected_versions_present":true,"cve_id":"CVE-2025-40538","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-40538","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-26T14:44:09.848Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-4_release_notes.htm","primary_source":"","published":"2026-02-24T07:40:12.958Z"},{"affected":"SolarWinds Serv-U 15.5.2 and prior versions","affected_versions_present":true,"cve_id":"CVE-2025-40549","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-40549","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-26T16:56:45.533Z","patch_url":"https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40549","primary_source":"","published":"2025-11-18T08:41:24.582Z"},{"affected":"Serv-U: SolarWinds Serv-U 15.5.2 and prior versions","affected_versions_present":true,"cve_id":"CVE-2025-40548","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-40548","fixed":"SolarWinds recommends that customers upgrade to SolarWinds Serv-U 15.5.3 as soon as it becomes available.","last_modified":"2026-02-26T16:56:45.923Z","patch_url":"https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40548","primary_source":"","published":"2025-11-18T08:38:19.354Z"},{"affected":"SolarWinds Serv-U 15.5.2 and prior versions","affected_versions_present":true,"cve_id":"CVE-2025-40547","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-40547","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-26T16:56:46.272Z","patch_url":"","primary_source":"","published":"2025-11-18T08:35:03.970Z"},{"affected":"Serv-U 15.5 and previous versions","affected_versions_present":true,"cve_id":"CVE-2024-45712","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-45712","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-15T13:58:41.012Z","patch_url":"https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-45712","primary_source":"","published":"2025-04-15T08:39:23.242Z"},{"affected":"Serv-U 15.4.2 HF 2 and previous versions","affected_versions_present":true,"cve_id":"CVE-2024-45711","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-45711","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-16T13:22:44.193Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av24-596","primary_source":"","published":"2024-10-16T07:27:22.001Z"},{"affected":"Serv-U 15.4.2 HF2 and previous versions","affected_versions_present":true,"cve_id":"CVE-2024-45714","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-45714","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-16T13:23:27.763Z","patch_url":"","primary_source":"","published":"2024-10-16T07:26:04.406Z"},{"affected":"SolarWinds Serv-U: 15.4.2 HF 1 and previous versions","affected_versions_present":true,"cve_id":"CVE-2024-28995","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-28995","fixed":"SolarWinds recommends that customers upgrade to SolarWinds Serv-U 15.4.2 HF 2 as soon as it becomes available.","last_modified":"2025-10-21T23:05:16.763Z","patch_url":"https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28995","primary_source":"","published":"2024-06-06T09:01:23.314Z"},{"affected":"15.4.2 and Previous Versions","affected_versions_present":true,"cve_id":"CVE-2024-28072","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-28072","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T00:48:48.228Z","patch_url":"","primary_source":"","published":"2024-05-03T07:50:00.696Z"},{"affected":"15.4 and previous versions","affected_versions_present":true,"cve_id":"CVE-2023-40053","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-40053","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T18:24:54.649Z","patch_url":"","primary_source":"","published":"2023-12-06T03:23:59.651Z"},{"affected":"15.4 \u2264 15.4 Hotfix 1","affected_versions_present":true,"cve_id":"CVE-2023-40060","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-40060","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-27T20:57:19.408Z","patch_url":"https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-4-0-Hotfix-2?language=en_US","primary_source":"","published":"2023-09-07T15:57:49.521Z"},{"affected":"15.4","affected_versions_present":true,"cve_id":"CVE-2023-35179","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35179","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-09T19:29:50.832Z","patch_url":"","primary_source":"","published":"2023-08-10T23:14:48.081Z"},{"affected":"15.3 and previous versions < 15.3.1","affected_versions_present":true,"cve_id":"CVE-2021-35249","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-35249","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T16:28:36.293Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-3-1_release_notes.htm","primary_source":"","published":"2022-05-17T19:44:55.183Z"},{"affected":"15.3 only < 15.3 Hotfix 1","affected_versions_present":true,"cve_id":"CVE-2021-35250","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-35250","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T23:31:12.506Z","patch_url":"https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-3-HotFix-1?language=en_US","primary_source":"","published":"2022-04-25T19:47:54.688Z"},{"affected":"Serv-U: 15.2.5 and previous versions < 15.3","affected_versions_present":true,"cve_id":"CVE-2021-35247","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-35247","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-21T23:15:49.752Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-3_release_notes.htm","primary_source":"","published":"2022-01-07T22:39:50.564Z"},{"affected":"15.2.3 and previous versions \u2264 15.2.4","affected_versions_present":true,"cve_id":"CVE-2021-35223","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-35223","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T00:33:51.260Z","patch_url":"https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-2-4_release_notes.htm","primary_source":"","published":"2021-08-31T16:00:18.000Z"},{"affected":"Serv-U Managed File Transfer Server and Serv-U Secured FTP: SolarWinds Serv-U < 15.2.3 HF1","affected_versions_present":true,"cve_id":"CVE-2021-35211","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-35211","fixed":"SolarWinds has released a hotfix 15.2.3 HF2 It is suggested to upgrade to the latest hotfix as soon as possible","last_modified":"2025-10-21T23:25:40.369Z","patch_url":"https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211","primary_source":"","published":"2021-07-14T20:55:25.167Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"SolarWinds"}}
