Critical SolarWinds Serv-U Vulnerabilities Enable Remote Root Access
SolarWinds has issued a critical security update for its Serv-U file transfer software, addressing four vulnerabilities that could permit attackers to execute arbitrary code with root-level privileges on affected servers. All four vulnerabilities have a…
SolarWinds has issued a critical security update for its Serv-U file transfer software, addressing four vulnerabilities that could permit attackers to execute arbitrary code with root-level privileges on affected servers. All four vulnerabilities have a CVSS score of 9.1, categorizing them as Critical. These issues have been resolved in Serv-U version 15.5.4, released on Mon, Feb 24, 2026.
Serv-U is a widely utilized file transfer server solution that supports secure file exchanges over FTP, FTPS, SFTP, and HTTP/S protocols. It is commonly used by organizations to manage data transfers between internal teams and external partners. Its extensive deployment in enterprise environments makes it a significant target for threat actors seeking access to sensitive organizational data.
The most severe of the four vulnerabilities, CVE-2025-40538, is a broken access control flaw that enables an attacker with domain admin or group admin privileges to create a system administrator account and execute arbitrary code as root. This vulnerability provides a direct path to full administrative control over the affected system.
The other three vulnerabilities further increase the threat level. CVE-2025-40539 and CVE-2025-40540 are type confusion vulnerabilities in Serv-U’s native code handling, which allow attackers to execute arbitrary native code as root due to memory-safety failures. CVE-2025-40541 is an Insecure Direct Object Reference (IDOR) flaw that also enables root-level native code execution when exploited.
Exploitation of all four vulnerabilities requires administrative privileges. On Windows deployments, the risk is rated medium since Serv-U services typically operate under less-privileged service accounts by default.
All four vulnerabilities have a CVSS score of 9.1, categorizing them as Critical.
CVE ID Vulnerability Type Description CVSS Score Severity
CVE-2025-40538 Broken Access Control RCE Allows attacker to create a system admin user and execute arbitrary code as root via domain/group admin privileges 9.1 Critical
CVE-2025-40539 Type Confusion RCE Allows attacker to execute arbitrary native code as root 9.1 Critical
CVE-2025-40540 Type Confusion RCE Allows attacker to execute arbitrary native code as root 9.1 Critical
CVE-2025-40541 IDOR RCE Allows attacker to execute native code as root 9.1 Critical
While SolarWinds has not confirmed active exploitation of these vulnerabilities, the history of exploitation within the software underscores the need for immediate action. Previous Serv-U vulnerabilities, such as CVE-2021-35211 and CVE-2024-28995, were actively exploited by threat actors, including the group tracked as Storm-0322. In June 2024, CVE-2024-28995, a path traversal flaw, was rapidly weaponized using publicly available proof-of-concept exploits post-disclosure.
SolarWinds has addressed all four vulnerabilities in Serv-U 15.5.4. Organizations using any version of Serv-U 15.5 or earlier are advised to upgrade immediately. Versions 15.5.1 and below reached End-of-Engineering as of Tue, Feb 18, 2026, and will not receive further security patches.
Based on reporting by GBHackers.
