Documentation forServ-U MFT & Serv-U FTP Server

Serv-U 2026.3 release notes

Release date: July 21, 2026

Here's what's new in Serv-U 2026.3. You can find the applicable system requirements here.

To view release notes, system requirements, and product guide PDFs for supported versions of Serv-U, see Serv-U previous versions. To view release notes for multiple versions and multiple SolarWinds Platform products on a single page, see the release notes aggregator.

New features and improvements in Serv-U

MFA for Active Directory LDAP users

Multi-factor authentication is currently available for local and database users. In Serv-U 2026.3, it has been extended to include both Microsoft Windows (Active Directory) and LDAP users.

Restored THWACK links

Serv-U's THWACK community page embedded view in the Serv-U Management Console has been removed due to security restrictions. You can now launch THWACK in another tab from both Serv-U Management Console and Serv-U Client.

File Upload has returned to the Send Files Share Link workflow

The creation of a file share link and file upload can once again be performed in a single workflow. In addition, the workflow now exists as an enhanced, three-step wizard that allows files to be uploaded before the link is shared.

Support for RHEL 9 and CentOS 9

Serv-U now supports Red Hat Enterprise Linux 9 and CentOS 9.

Content Security Policies have been hardened

Content Security Policies (CSPs) for Serv-U have been hardened, enhancing code injection prevention.

Permissions-Policy now configurable by the customer

Serv-U 2026.3 introduces the Permissions-Policy under the Limits and Settings section so that it is now configurable by the customer, with access restricted to system administrators.

Enhanced File Share user experience

Guest and owner views now feature better handling of stake File Share pages (files that have been deleted or added without refreshing) with user-friendly messaging rather than browser errors.

Improved Serv-U Client reliability and compatibility

A Safari rendering issue that previously hid folders in the Serv-U Client has been corrected.

Free FTP Voyager tool now available again to complement Serv-U

You can once again take advantage of FTP Voyager, which complements Serv-U by adding a rich, user-friendly file transfer client stand-alone application with synchronization, transfer management, and secure file movement capabilities, making Serv-U more efficient.

General improvements

  • Updated OpenSSL for performance updates and security updates available in version 3.0.21.
  • Security improvements
  • Functionality fixes

Fixed CVEs

At SolarWinds, we prioritize the swift resolution of CVEs to ensure the security and integrity of our software. In this release, we have successfully addressed the following CVEs.

SolarWinds CVEs

SolarWinds would like to thank our Security Researchers below for reporting on the issue in a responsible manner and working with our security, product, and engineering teams to fix the vulnerability.

CVE-ID Vulnerability Title Description Severity Credit
CVE-2026-28302 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28304 SolarWinds Serv-U Remote Code Execution Vulnerability SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28305 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28306 SolarWinds Serv-U Privilege Escalation Vulnerability SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28307 SolarWinds Serv-U Privilege Escalation Vulnerability SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28308 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28309 SolarWinds Serv-U Broken Access Control Vulnerability SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28310 SolarWinds Serv-U Privilege Escalation Vulnerability SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28311 SolarWinds Serv-U Remote Code Execution Vulnerability SolarWinds Serv-U is affected by a remote code execution vulnerability that allows a domain administrator to modify how the application behaves, which can lead to remote code execution. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28312 SolarWinds Serv-U Privilege Escalation Vulnerability SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28313 Serv-U Insecure Direct Object Reference (IDOR) Vulnerability SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28314 SolarWinds Serv-U Insecure Direct Object Reference Vulnerability SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28315 SolarWinds Serv-U Stored Cross-site Scripting (XSS) Vulnerability SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account. 6.2 Medium  
CVE-2026-28316 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28317 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments. 9.1 Critical Intigriti Bug Bounty Program
CVE-2026-28321 SolarWinds Serv-U Broken Access Control Vulnerability SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator is required, and the impact is lower in Windows installations. 9.1 Critical Intigriti Bug Bounty Program

Fixed customer issues

Case number Description
02116335 Serv-U no longer crashes with the irrelevant "content-encoding: deflate" HTTP header.
N/A Anonymous SSH FTP session no longer disrupts Serv-U functioning.
02025152 Anonymous and FTP LDP users can again log in.
01720517 Serv-U sendfile no longer causes incorrect file downloads.
01744050 02010260 Links from shared 'file uploaded' and 'file downloaded' notifications work properly.
N/A The Time&Date expiration in the File Share title corresponds to the set expiration date and time unless the user modifies the title after setting the expiration. If the title is manually modified after the expiration has been set, the title no longer auto-updates based on expiration.
N/A Logging is now consistent when uploads fail due to "Maximum upload file size" limits. FTP/SFTP now log correct outcomes.
01727052 Serv-U allows simple expressions as virtual host names and does not require top-level domain names.
01794765 02108572 02086408 02083637 Serv-U connects to the ODBC without errors upon startup.
N/A Remnants of the FTP Voyager JV client that were not removed during Linux upgrades of Serv-U have now been fully removed from Serv-U.
02044119 Serv-U responds correctly to the cd /name*with*wildcard command.
N/A Serv-U now displays a list of responses in the FTP command properties user interface.
N/A Serv-U prevents permission changes that could enable execution of uploaded files.
N/A The correct Content-Security-Policy is applied for the Serv-U Client.
N/A Toast messaging and auto-refreshes display rather than "404 not found" for deleted files.
N/A The "Download All" behavior has been improved when the file lists changes without being refreshed.
N/A Owner view downloads has been improved for stale file lists.
02078166 Serv-U Thwack community page now successfully opens in a new tab instead of being embedded inside Serv-U.
02025152 Anonymous user logins are no longer rejected with invalid password errors in the UI.
01469757 01426672 Files upload successfully under Gateway and TLS v1.3.
01287592 Domain log path name resolves correctly.
01235477 01399014 01795582 All files are current as expected and displaying correctly in the Serv-U Client.
02073454 The following headers were implemented to enhance web server security: Permission-Policy, Cross-Origin-Embedder-Policy, Cross-Origin-Resource-Policy, and Cross-Origin-Opener-Policy.
02073107 02074467 02052227 02049061 02010202 01978308 Users can upload a file during the initial share creation process within the Serv-U Client, effectively combining the "create share" and "upload file" steps into one seamless action so that recipients never receive a link to an empty file list.
02089342

Serv-U is compatible with AWS account name formatting (key ID format), so customers can successfully enable SMTP setup.

02035472 The 'report-to' directive is no longer missing from the Content Security Policy (CSP) reporting features in Serv-U. With both 'report-to' and 'report-uri' directives included in the CSP header, visibility into security violations are improved.
N/A Corrupt file issue has been corrected.
N/A Web Client Login page loads properly in Firefox when the browser is updated to the most recent version.
N/A LDAP property details are correctly saved and displayed in Serv-U.
N/A The toast message is correctly displayed in front of the dialog on small screens.
N/A The multi-factor authentication (MFA) setup screen displays a valid QR code and a manual configuration key to allow proper MFA authentication setup.
N/A When a file share has already expired, the user encounters an error message that states File share link expired. The user is then unable to click on the Upload button and cannot drag and drop files.

Installation or upgrade

For new installations, you can download the installation file from the Serv-U product page on https://www.solarwinds.com or from the Customer Portal. For more information, see Install the SolarWinds Serv-U File Server.

For more information about upgrades, see Upgrade Serv-U File Server.

End of life

Version EoL announcement EoE effective date EoL effective date
15.5.1 November 18, 2025: End-of-Life (EoL) announcement – Customers on Serv-U version 15.5.1 or earlier should begin transitioning to the latest version of Serv-U. February 18, 2026: End-of-Engineering (EoE) – Service releases, bug fixes, workarounds, and service packs for Serv-U version 15.5.1 or earlier will no longer actively be supported by SolarWinds. November 18, 2026: End-of-Life (EoL) – SolarWinds will no longer provide technical support for Serv-U version 15.5.1.
15.5 July 8, 2025: End-of-Life (EoL) announcement – Customers on Serv-U version 15.5 or earlier should begin transitioning to the latest version of Serv-U. October 8, 2025: End-of-Engineering (EoE) – Service releases, bug fixes, workarounds, and service packs for Serv-U version 15.5 or earlier will no longer actively be supported by SolarWinds. October 8, 2026: End-of-Life (EoL) – SolarWinds will no longer provide technical support for Serv-U version 15.5.

See the End of Life Policy for information about SolarWinds product life cycle phases. To see EoL dates for earlier Serv-U versions, see Serv-U release history.

Legal notices

© 2026 SolarWinds Worldwide, LLC. All rights reserved.

This document may not be reproduced by any means nor modified, decompiled, disassembled, published or distributed, in whole or in part, or translated to any electronic medium or other means without the prior written consent of SolarWinds. All right, title, and interest in and to the software, services, and documentation are and shall remain the exclusive property of SolarWinds, its affiliates, and/or its respective licensors.

SOLARWINDS DISCLAIMS ALL WARRANTIES, CONDITIONS, OR OTHER TERMS, EXPRESS OR IMPLIED, STATUTORY OR OTHERWISE, ON THE DOCUMENTATION, INCLUDING WITHOUT LIMITATION NONINFRINGEMENT, ACCURACY, COMPLETENESS, OR USEFULNESS OF ANY INFORMATION CONTAINED HEREIN. IN NO EVENT SHALL SOLARWINDS, ITS SUPPLIERS, NOR ITS LICENSORS BE LIABLE FOR ANY DAMAGES, WHETHER ARISING IN TORT, CONTRACT OR ANY OTHER LEGAL THEORY, EVEN IF SOLARWINDS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

The SolarWinds, SolarWinds & Design, Orion, and THWACK trademarks are the exclusive property of SolarWinds Worldwide, LLC or its affiliates, are registered with the U.S. Patent and Trademark Office, and may be registered or pending registration in other countries. All other SolarWinds trademarks, service marks, and logos may be common law marks or are registered or pending registration. All other trademarks mentioned herein are used for identification purposes only and are trademarks of (and may be registered trademarks) of their respective companies.