>> All posts

CVE-2021-35211: SolarWinds Serv-U remote code execution, exploited in the wild

The short version: SolarWinds Serv-U (Managed File Transfer and Secure FTP) has a memory-corruption flaw (CVE-2021-35211) that lets a remote attacker execute code on the host, potentially with privileged access. It was exploited in the wild as a targeted zero-day, and it's in CISA's KEV catalog. If you run an affected build on the internet, this is patch-and-verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — bordering Critical (see below)
CVSS v3.1 (NVD)9.0 — Critical · AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS91.16% · 99.8th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2021-11-17
Known exploited?Yes — exploited as a targeted zero-day; CISA notes known ransomware use
Vulnerability typeCWE-787 out-of-bounds write → remote code execution with privileged access
Requires authenticated session?No — pre-authentication
AffectedSolarWinds Serv-U 15.2.3 Hotfix 1 and earlier
Fixed inServ-U 15.2.3 Hotfix 2 (15.2.3.717) or later

What you need to know

CVE-2021-35211 is an out-of-bounds write in Serv-U's memory handling. A remote attacker who can reach the service — over SSH/Secure FTP in the reported exploitation — can corrupt memory and, when it works, execute code on the host. SolarWinds and Microsoft documented a single, sophisticated actor exploiting it in a limited, targeted campaign before the fix.

Why the practical risk is high despite a higher attack complexity:

  • It's the file-transfer server itself. Code execution there reaches the files it moves and the host it runs on.
  • It was a real zero-day. Exploitation preceded the patch, so an affected, exposed appliance may have been touched before you had a fix.
  • CISA flags ransomware use. The catalog marks this one as associated with known ransomware campaigns — a signal to prioritize it even though initial exploitation was targeted.

How serious we see it

High — bordering Critical.

NVD scores it 9.0 (Critical), tempered by a higher attack complexity (AC:H) — reliable exploitation isn't trivial. We land on High rather than automatically Critical because the confirmed activity was limited and targeted rather than mass exploitation, and the bug is harder to weaponize than a clean command injection. But it's unauthenticated code execution on an internet-facing file server, it's in KEV, and CISA notes ransomware association — so treat it firmly, not casually. The reassuring part: specific builds, a published fix, and quick exposure checks.

Recommendations

Straight from SolarWinds' advisory and CISA:

  1. Patch now. Upgrade to Serv-U 15.2.3 Hotfix 2 or later.
  2. Assume the zero-day window — hunt. Because exploitation predated the fix, review logs for anomalous SSH/Secure FTP activity and signs of code execution on the host.
  3. If you find indicators, respond fully. Rebuild where warranted and rotate all credentials, keys, and certificates on the device.
  4. Restrict reachability. Limit access to the Serv-U service to trusted IP addresses.
  5. Confirm your exposure first. Verify whether you run an affected, internet-facing Serv-U build.

How BreachRisk sees it

BreachRisk discovers internet-facing Serv-U instances from little more than your domain, fingerprints the product and version, and flags exposure tied to CVE-2021-35211 — raised to the top because it's in KEV. Because a safe check for this flaw isn't possible — verifying it means a memory write that can crash the service — BreachRisk detects and flags the exposed, affected version rather than attempting exploitation, so the assessment never risks knocking your server over.

That outside-in, continuous view is the point: when a file-server RCE surfaces, the exposed appliance is already mapped, so you go straight to patch-and-verify.

References

See your cyber risk, proven.