people · May 17, 2026
SolarWinds Patches Three Critical Serv-U Vulnerabilities
Share the canonical public link.
SolarWinds patched three critical vulnerabilities in Serv-U software on May 14, 2026. The vulnerabilities, identified as CVE-2023-3519, CVE-2023-3520, and CVE-2023-3521, involved improper input validation and buffer overflow issues that could allow arbitrary code execution or denial-of-service attacks. SolarWinds discovered the issues internally and released a security update with no reported active exploitation at the time of the patch. Serv-U is SolarWinds' file transfer and management product used by enterprise customers worldwide.