• News/
  • https://www.theregister.com/2026/02/24/patch_these_4_critical_makemeroot/

Patch these 4 critical, make-me-root SolarWinds bugs ASAP

The Register
·
Jessica Lyons
·
Published Feb 24, 2026
·
Updated

If you run SolarWinds’ Serv-U, you should patch promptly. Four critical vulnerabilities in the file transfer software can allow attackers to execute code as root. The four flaws, all of which earned a 9.1 CVSS rating, include a broken access control vulnerability (CVE-2025-40538), two type confusion bugs (CVE-2025-40540 and CVE-2025-40539), and an Insecure Direct Object Reference (IDOR) issue (CVE-2025-40541), all of which can lead to remote code execution (RCE). The most serious of the four, CVE-2025-40538, "gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges," according to the vendor's security advisory. Updating to the latest version, Serv-U 15.5.4, patches all four security holes. In a statement to The Register, SolarWinds said, "We are aware of the reported issues and successfully addressed them as part of the Serv-U 15.5.4 release. We have not observed exploitation. We remain committed to monitoring the situation, working closely with customers and partners to ensure issues are resolved quickly. SolarWinds continues to prioritize the swift resolution of CVEs to ensure the security and integrity of our software." The good news is that all four require administrative privileges to abuse, and none of the new CVEs have appeared on the US Cybersecurity and Infrastructure Security Agency's (CISA's) catalog of Known Exploited Vulnerabilities - yet. However, SolarWinds' p...

Read full article

Affected Software

1 affected component
SolarWinds Serv-U=15.5.4
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses four critical vulnerabilities in SolarWinds' Serv-U file transfer software that need urgent patching.

2

What security implications are discussed?

The vulnerabilities can allow attackers to execute code with root privileges, posing a significant security risk.

3

What software is affected by these vulnerabilities?

The affected software is SolarWinds' Serv-U version 15.5.4.

4

What is the severity rating of the vulnerabilities?

Each of the four vulnerabilities has a CVSS rating of 9.1, indicating critical severity.

5

What should users of SolarWinds Serv-U do in response to the article?

Users should promptly apply patches to mitigate the risks associated with the identified vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203