← Vulnerability feed

Vulnerability record · CVE-2021-35211 · published 14 July 2021

CVE-2021-35211: SolarWinds Serv-U out-of-bounds write enables remote code execution

Solarwinds · Serv U

SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 contain an out-of-bounds write (CWE-787) that Microsoft described as a remote memory escape leading to remote code execution. The flaw was exploited as a zero-day before patches were available, and it is listed in CISA's Known Exploited Vulnerabilities catalog.

10.0 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 91% · top 0.2% CWE-787 · Out-of-bounds write
10.0CVSS 3.1 base score, v2 10.0
91%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 10.0, unauthenticated network RCE, confirmed zero-day exploitation, KEV listing with ransomware use, and near-maximum EPSS make this an urgent patch-first issue.

What it is

SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 contain an out-of-bounds write (CWE-787) that Microsoft described as a remote memory escape leading to remote code execution. The flaw was exploited as a zero-day before patches were available, and it is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An unauthenticated attacker can execute code with privileged access on the machine hosting Serv-U, giving full control of that host and any data or credentials it handles.

Attack surface

The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the flaw is reachable over the network with no authentication and no user interaction, so any exposed Serv-U service is directly attackable.

Exploitation

CISA added it to KEV on 2021-11-03 with a 2021-11-17 remediation due date and flags known ransomware campaign use; EPSS is 0.9116 (99.8th percentile), and references are tagged Patch and Vendor Advisory, confirming active exploitation and available fixes.

What to do

  • Upgrade Serv-U Managed File Transfer and Serv-U Secure FTP for Windows to 15.2.3 HF2 or later.
  • If immediate patching is not possible, restrict network access to the Serv-U service to trusted hosts only.
  • Place Serv-U behind a firewall or VPN and avoid exposing it directly to the internet.
  • Monitor vendor advisories for follow-up fixes and verify the installed build after upgrading.
  • Review host logs for signs of compromise on any Serv-U server that was internet-exposed before patching.

Detection

  • Hunt for unexpected child processes spawned by the Serv-U service, especially command shells or scripting interpreters.
  • Monitor Serv-U logs and host telemetry for crashes, memory errors or abnormal service restarts.
  • Alert on outbound connections from Serv-U hosts to unfamiliar external addresses.
  • Correlate Serv-U host activity with known post-exploitation behavior such as credential access or lateral movement.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-35211 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SolarWinds Serv-U Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35211 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-28318SolarWinds Serv-U unauthenticated POST request denial of serviceSolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authenticat…KEVEPSS 1.9%analysed7.5CVE-2024-28995SolarWinds Serv-U path traversal allows arbitrary file readSolarWinds Serv-U contains a path traversal flaw (CWE-22) that lets an unauthenticated remote attacker read sensitive files from the host. The vulner…KEVEPSS 100%analysed5.3CVE-2021-35247SolarWinds Serv-U web login LDAP input validation flawThe Serv-U web login screen passed characters to LDAP authentication without sufficient sanitization. SolarWinds updated the input mechanism to add v…KEVEPSS 3.5%analysed9.8CVE-2020-35481Solarwinds serv-u vulnerabilitySolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.EPSS 1.3%9.1CVE-2026-28317Solarwinds serv-u insecure direct object reference vulnerabilitySolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires …EPSS 0.50%9.1CVE-2026-28321Solarwinds serv-u improper access control vulnerabilitySolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to esca…EPSS 0.58%9.1CVE-2026-28312Solarwinds serv-u improper authorization vulnerabilitySolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code exe…EPSS 0.58%9.1CVE-2026-28313Solarwinds serv-u insecure direct object reference vulnerabilitySolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary accoun…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2021-35211), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.