Vulnerabilities SolarWinds Patches Four Critical Serv-U Vulnerabilities The four security defects could be exploited for remote code execution but require administrative privileges. By Ionut Arghire | February 25, 2026 (10:30 AM ET) Flipboard Reddit Whatsapp Whatsapp Email SolarWinds on Tuesday announced patches for four critical-severity vulnerabilities in its enterprise file transfer solution, Serv-U. All four security defects, tracked as CVE-2025-40538 to CVE-2025-40541, have a CVSS score of 9.1, could result in remote code execution, and impact Serv-U version 15.5. CVE-2025-40538, SolarWinds explains, is a broken access control issue that could allow threat actors to create a system admin user and execute arbitrary code with the elevated privileges of domain admin or group admin. CVE-2025-40539 and CVE-2025-40540 are type confusion flaws that allow attackers to execute code with elevated privileges, the company notes, without providing additional details. CVE-2025-40541 is described as an insecure direct object reference (IDOR) bug leading to the execution of native code in the context of a privileged account. The successful exploitation of all four vulnerabilities, SolarWinds explains, requires that an attacker have administrative privileges on the vulnerable Serv-U instance. Advertisement. Scroll to continue reading. âOn Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default,â the company says. All four CVEs were resolved with the release of SolarWinds Serv-U version 15.5.4. Additional information can be found on SolarWindsâ security advisories page. SolarWinds makes no mention of any of these flaws being exploited in the wild, but users are advised to update their instances as soon as possible. Threat actors are known to target SolarWinds bugs in attacks, including issues affecting the Serv-U file transfer appliances. In late January, SolarWinds rolled out fixes for Web Help Desk (WHD) security defects that had been potentially exploited as zero-days in attacks observed in December 2025. In mid-February, the US cybersecurity agency CISA added one of the issues to its Known Exploited Vulnerabilities (KEV) list. Related: VMware Aria Operations Vulnerability Could Allow Remote Code Execution Related: Taiwan Security Firm Confirms Flaw Flagged by CISA Likely Exploited by Chinese APTs Related: Recent RoundCube Webmail Vulnerability Exploited in Attacks Related: Critical Grandstream Phone Vulnerability Exposes Calls to Interception Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. More from Ionut Arghire Ad Tech Company Optimizely Targeted in Cyberattack âArkanix Stealerâ Malware Disappears Shortly After Debut New âSandworm_Modeâ Supply Chain Attack Hits NPM GitHub Issues Abused in Copilot Attack Leading to Repository Takeover Anonymous FĂ©nix Members Arrested in Spain Ukrainian Gets 5 Years in US Prison for Aiding North Korean IT Fraud Romanian Hacker Pleads Guilty to Selling Access to US State Network Hundreds of FortiGate Firewalls Hacked in AI-Powered Attacks: AWS Latest News Medical Device Maker UFP Technologies Hit by Cyberattack Ex-US Defense Contractor Executive Jailed for Selling Exploits to Russia Over 12 Million Users Impacted by CarGurus Data Breach SecurityWeek Report: 426 Cybersecurity M&A Deals Announced in 2025 Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site Astelia Raises $35 Million for Exposure Management Reddit Hit With $20 Million UK Data Privacy Fine Over Child Safety Failings Claudeâs New AI Vulnerability Scanner Sends Cybersecurity Shares Plunging Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeekâs 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize todayâs ransomware extortion threats. Submit People on the Move Wealth management platform Envestnet announced the appointment of Rich Friedberg as CISO. Yuneeb Khan has been named Chief Financial Officer of KnowBe4, succeeding Bob Reich, who is retiring. Cyera has appointed Brandon Sweeney as President, Shira Azran as Chief Legal Officer and Joseph Iantosca as Chief Financial Officer. More People On The Move Expert Insights How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures donât always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isnât a hypothetical but a natural continuation of the tradecraft weâve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Canât Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Flipboard Reddit Whatsapp Whatsapp Email
SolarWinds has patched four critical vulnerabilities (CVE-2025-40538 through CVE-2025-40541, CVSS 9.1) in its Serv-U file transfer solution, including broken access control, type confusion, and IDOR flaws that could lead to remote code execution with elevated privileges. These vulnerabilities affect Serv-U versions prior to 15.5.4, and the fix requires an immediate upgrade to version 15.5.4. Successful exploitation requires the attacker to already possess administrative privileges on the target instance.