If you run SolarWinds’ Serv-U, you should patch promptly. Four critical vulnerabilities in the file transfer software can allow attackers to execute code as root. The four flaws, all of which earned a 9.1 CVSS rating, include a broken access control vulnerability (CVE-2025-40538), two type confusion bugs (CVE-2025-40540 and CVE-2025-40539), and an Insecure Direct Object Reference (IDOR) issue (CVE-2025-40541), all of which can lead to remote code execution (RCE). The most serious of the four, CVE-2025-40538, "gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges," according to the vendor's security advisory. Updating to the latest version, Serv-U 15.5.4, patches all four security holes. In a statement to The Register, SolarWinds said, "We are aware of the reported issues and successfully addressed them as part of the Serv-U 15.5.4 release. We have not observed exploitation. We remain committed to monitoring the situation, working closely with customers and partners to ensure issues are resolved quickly. SolarWinds continues to prioritize the swift resolution of CVEs to ensure the security and integrity of our software." The good news is that all four require administrative privileges to abuse, and none of the new CVEs have appeared on the US Cybersecurity and Infrastructure Security Agency's (CISA's) catalog of Known Exploited Vulnerabilities - yet. However, SolarWinds' p...
Patch these 4 critical, make-me-root SolarWinds bugs ASAP
The Register
·Jessica Lyons
·Published Feb 24, 2026
·Updated
Affected Software
1 affected component
SolarWinds Serv-U=15.5.4
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses four critical vulnerabilities in SolarWinds' Serv-U file transfer software that need urgent patching.
2
What security implications are discussed?
The vulnerabilities can allow attackers to execute code with root privileges, posing a significant security risk.
3
What software is affected by these vulnerabilities?
The affected software is SolarWinds' Serv-U version 15.5.4.
4
What is the severity rating of the vulnerabilities?
Each of the four vulnerabilities has a CVSS rating of 9.1, indicating critical severity.
5
What should users of SolarWinds Serv-U do in response to the article?
Users should promptly apply patches to mitigate the risks associated with the identified vulnerabilities.