SolarWinds has released security updates to patch four critical Serv-U remote code execution vulnerabilities that could grant attackers root access to unpatched servers. Serv-U is the company's self-hosted Windows and Linux file transfer software that comes with both Managed File Transfer (MFT) and FTP server capabilities, enabling organizations to securely exchange files via FTP, FTPS, SFTP, and HTTP/S. The most severe of the four security flaws patched by SolarWinds today in Serv-U 15.5.4 is tracked as CVE-2025-40538, and it allows attackers with high privileges to gain root or admin permissions on vulnerable servers. "A broken access control vulnerability exists in Serv-U which, when exploited, gives an attacker the ability to create a system admin user and execute arbitrary code as root via domain admin or group admin privileges," SolarWinds said in a Tuesday advisory. The company also patched two type confusion flaws and an Insecure Direct Object Reference (IDOR) vulnerability that can be exploited to gain code execution with root privileges. Luckily, all four security flaws require attackers to already have high privileges on the targeted servers, which will limit potential exploitation attempts to scenarios where attackers can chain privilege escalation vulnerabilities or use previously stolen admin credentials. Shodan currently tracks over 12,000 Internet-exposed Serv-U servers, while Shadowserver estimates the number to be less than 1,200. File transfer software li...
Critical SolarWinds Serv-U flaws offer root access to servers
BleepingComputer
·Sergiu Gatlan
·Published Feb 24, 2026
·Updated
Affected Software
1 affected component
SolarWinds Serv-U>=15.5.4
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses critical vulnerabilities in SolarWinds Serv-U that can allow attackers to gain root access to servers.
2
What security implications are discussed?
The vulnerabilities can lead to remote code execution, potentially allowing unauthorized access and control of affected servers.
3
What products or software are affected?
The affected software is SolarWinds Serv-U, specifically from version 15.5.4.
4
How can users protect themselves from these vulnerabilities?
Users are advised to apply the latest security updates released by SolarWinds to patch the vulnerabilities.
5
What action has SolarWinds taken regarding these vulnerabilities?
SolarWinds has released security updates to address the identified vulnerabilities in Serv-U.