https://reddit.com/r/cybersecurity/comments/1rflba8/cve202540540_cvss_91_solarwinds_servu_critical/: CVE-2025-40540 (CVSS 9.1) — SolarWinds Serv-U Critical Vulnerability (Type Confusion RCE) — Patch Released
Published Feb 26, 2026
·Updated
Affected Software
1 affected component
SolarWinds Serv-U<15.5.4
Frequently Asked Questions
1
What is the severity of CVE-2025-40540?
CVE-2025-40540 is rated with a CVSS score of 9.1, indicating a critical severity level.
2
How do I fix CVE-2025-40540?
To fix CVE-2025-40540, update SolarWinds Serv-U to version 15.5.4 or later.
3
What type of vulnerability is CVE-2025-40540?
CVE-2025-40540 is a type confusion vulnerability that enables remote code execution.
4
What are the potential impacts of CVE-2025-40540?
The potential impacts of CVE-2025-40540 include arbitrary native code execution with elevated privileges.
5
Is CVE-2025-40540 being actively exploited?
While specific exploitation details are not disclosed, the critical nature of CVE-2025-40540 suggests it could be targeted by attackers.