SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Serv-U Vulnerabilities Expose Systems to Root Compromise

Serv-U Vulnerabilities Expose Systems to Root Compromise

SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if successfully exploited, could result in remote code execution. These vulnerabilities affect SolarWinds Serv-U version 15.5 and have been addressed in version 15.5.4.

Feb 25, 2026By Meghana Raatni2 min read

SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if successfully exploited, could result in remote code execution. These vulnerabilities affect SolarWinds Serv-U version 15.5 and have been addressed in version 15.5.4.

Vulnerability Details

The most severe of the four security flaws patched is tracked as CVE-2025-40538, and it allows attackers with high privileges to gain root or admin permissions on vulnerable servers. All four flaws have a CVSS score of 9.1 and require administrative privileges for successful exploitation.

The vulnerabilities include:

  • CVE-2025-40538: A broken access control flaw that enables a user with domain or group administrator privileges to create a system administrator account and execute arbitrary code with root-level permissions.
  • CVE-2025-40539: A type confusion vulnerability that can allow an authenticated administrator to execute arbitrary native code with root privileges.
  • CVE-2025-40540: A separate type confusion issue that similarly permits execution of arbitrary native code as root.
  • CVE-2025-40541: An insecure direct object reference (IDOR) vulnerability that may allow an administrator-level user to execute native code with root-level access.

Affected Products

The vulnerabilities affect SolarWinds Serv-U version 15.5. These have been addressed in SolarWinds Serv-U version 15.5.4.

Mitigation

To mitigate the risk from these vulnerabilities, SolarWinds recommends updating to Serv-U version 15.5.4 as soon as possible.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026