SolarWinds has issued fixes for four critical vulnerabilities impacting its Serv-U self-hosted Windows and Linux file transfer software, which could be weaponized to enable remote code execution, according to The Register.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory detailing a "missing authentication for critical function" flaw, tracked as CVE-2026-1670, with a CVSS score of 9.8 out of 10.