Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical SolarWinds Serv-U Vulnerabilities Enable Remote Root Access

SolarWinds has issued a critical security update for its Serv-U file transfer software, addressing four vulnerabilities that could permit attackers to execute arbitrary code with root-level privileges on affected servers. All four vulnerabilities have a…

SolarWinds has issued a critical security update for its Serv-U file transfer software, addressing four vulnerabilities that could permit attackers to execute arbitrary code with root-level privileges on affected servers. All four vulnerabilities have a CVSS score of 9.1, categorizing them as Critical. These issues have been resolved in Serv-U version 15.5.4, released on Mon, Feb 24, 2026.

Serv-U is a widely utilized file transfer server solution that supports secure file exchanges over FTP, FTPS, SFTP, and HTTP/S protocols. It is commonly used by organizations to manage data transfers between internal teams and external partners. Its extensive deployment in enterprise environments makes it a significant target for threat actors seeking access to sensitive organizational data.

The most severe of the four vulnerabilities, CVE-2025-40538, is a broken access control flaw that enables an attacker with domain admin or group admin privileges to create a system administrator account and execute arbitrary code as root. This vulnerability provides a direct path to full administrative control over the affected system.

The other three vulnerabilities further increase the threat level. CVE-2025-40539 and CVE-2025-40540 are type confusion vulnerabilities in Serv-U’s native code handling, which allow attackers to execute arbitrary native code as root due to memory-safety failures. CVE-2025-40541 is an Insecure Direct Object Reference (IDOR) flaw that also enables root-level native code execution when exploited.

Exploitation of all four vulnerabilities requires administrative privileges. On Windows deployments, the risk is rated medium since Serv-U services typically operate under less-privileged service accounts by default.

All four vulnerabilities have a CVSS score of 9.1, categorizing them as Critical.
Rachel Green · Thehackingpost

CVE ID Vulnerability Type Description CVSS Score Severity

CVE-2025-40538 Broken Access Control RCE Allows attacker to create a system admin user and execute arbitrary code as root via domain/group admin privileges 9.1 Critical

CVE-2025-40539 Type Confusion RCE Allows attacker to execute arbitrary native code as root 9.1 Critical

CVE-2025-40540 Type Confusion RCE Allows attacker to execute arbitrary native code as root 9.1 Critical

Advertisement

CVE-2025-40541 IDOR RCE Allows attacker to execute native code as root 9.1 Critical

While SolarWinds has not confirmed active exploitation of these vulnerabilities, the history of exploitation within the software underscores the need for immediate action. Previous Serv-U vulnerabilities, such as CVE-2021-35211 and CVE-2024-28995, were actively exploited by threat actors, including the group tracked as Storm-0322. In June 2024, CVE-2024-28995, a path traversal flaw, was rapidly weaponized using publicly available proof-of-concept exploits post-disclosure.

SolarWinds has addressed all four vulnerabilities in Serv-U 15.5.4. Organizations using any version of Serv-U 15.5 or earlier are advised to upgrade immediately. Versions 15.5.1 and below reached End-of-Engineering as of Tue, Feb 18, 2026, and will not receive further security patches.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories