• News/
  • https://www.bleepingcomputer.com/news/security/critical-solarwinds-serv-u-flaws-offer-root-access-to-servers/

Critical SolarWinds Serv-U flaws offer root access to servers

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 24, 2026
·
Updated

SolarWinds has released security updates to patch four critical Serv-U remote code execution vulnerabilities that could grant attackers root access to unpatched servers. Serv-U is the company's self-hosted Windows and Linux file transfer software that comes with both Managed File Transfer (MFT) and FTP server capabilities, enabling organizations to securely exchange files via FTP, FTPS, SFTP, and HTTP/S. The most severe of the four security flaws patched by SolarWinds today in Serv-U 15.5.4 is tracked as CVE-2025-40538, and it allows attackers with high privileges to gain root or admin permissions on vulnerable servers. "A broken access control vulnerability exists in Serv-U which, when exploited, gives an attacker the ability to create a system admin user and execute arbitrary code as root via domain admin or group admin privileges," SolarWinds said in a Tuesday advisory. The company also patched two type confusion flaws and an Insecure Direct Object Reference (IDOR) vulnerability that can be exploited to gain code execution with root privileges. Luckily, all four security flaws require attackers to already have high privileges on the targeted servers, which will limit potential exploitation attempts to scenarios where attackers can chain privilege escalation vulnerabilities or use previously stolen admin credentials. Shodan currently tracks over 12,000 Internet-exposed Serv-U servers, while Shadowserver estimates the number to be less than 1,200. ​File transfer software li...

Read full article

Affected Software

1 affected component
SolarWinds Serv-U>=15.5.4
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses critical vulnerabilities in SolarWinds Serv-U that can allow attackers to gain root access to servers.

2

What security implications are discussed?

The vulnerabilities can lead to remote code execution, potentially allowing unauthorized access and control of affected servers.

3

What products or software are affected?

The affected software is SolarWinds Serv-U, specifically from version 15.5.4.

4

How can users protect themselves from these vulnerabilities?

Users are advised to apply the latest security updates released by SolarWinds to patch the vulnerabilities.

5

What action has SolarWinds taken regarding these vulnerabilities?

SolarWinds has released security updates to address the identified vulnerabilities in Serv-U.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203