SolarWinds Patches Critical Flaws in Serv-U File Transfer Tool

by Anika Shah - Technology
0 comments

SolarWinds Patches Critical Serv-U Flaws Enabling Root Access

SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if exploited, could allow attackers to gain remote code execution and potentially root access to servers. The vulnerabilities affect SolarWinds Serv-U version 15.5 and have been addressed in version 15.5.4.

Vulnerability Details

All four vulnerabilities received a CVSS score of 9.1, indicating critical severity. They are:

  • CVE-2025-40538: A broken access control vulnerability allowing an attacker to create a system admin user and execute arbitrary code as root with domain or group admin privileges. The Hacker News
  • CVE-2025-40539: A type confusion vulnerability enabling an attacker to execute arbitrary native code as root. The Hacker News
  • CVE-2025-40540: Another type confusion vulnerability allowing an attacker to execute arbitrary native code as root. The Hacker News
  • CVE-2025-40541: An insecure direct object reference (IDOR) vulnerability allowing an attacker to execute native code as root. The Hacker News

Exploitation and Mitigation

SolarWinds stated that exploitation of these vulnerabilities requires administrative privileges. However, the company noted that on Windows deployments, the services “frequently run under less-privileged service accounts by default,” potentially mitigating the risk. The Hacker News

As of February 25, 2026, SolarWinds has not observed any evidence of these vulnerabilities being exploited in the wild. BleepingComputer, The Hacker News. The company encourages all customers to upgrade to version 15.5.4 immediately.

Past Vulnerabilities and Threat Actors

SolarWinds has a history of vulnerabilities in its software, including CVE-2021-35211, CVE-2021-35247, and CVE-2024-28995, which have been exploited by malicious actors, including the China-based hacking group Storm-0322 (formerly DEV-0322). The Hacker News

Serv-U and Managed File Transfer Security

Serv-U is a widely used file transfer server software that supports protocols like FTP, FTPS, SFTP, and HTTP/S. Managed file transfer (MFT) solutions, like Serv-U, are frequent targets for cyberattacks. Notable past incidents include the 2023 MOVEit attacks, which impacted over 2,700 organizations worldwide, and attacks targeting GoAnywhere. CSO Online

Related Posts

Leave a Comment