Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

SolarWinds Critical Serv-U Vulnerabilities Enables Root Access

An urgent security update has been released for the Serv-U file server software to address multiple critical vulnerabilities that could allow attackers to compromise affected systems completely.

An urgent security update has been released for the Serv-U file server software to address multiple critical vulnerabilities that could allow attackers to compromise affected systems completely.

The latest version, Serv-U 15.5.4, resolves four high-severity security flaws, each with a CVSS score of 9.1.

These vulnerabilities are particularly dangerous as they enable remote code execution , providing attackers with the highest level of administrative control over the targeted infrastructure.

Cybersecurity teams and system administrators are advised to review the release notes and apply the updates immediately to prevent potential exploitation.

Serv-U Vulnerabilities Enable Root Access

The newly disclosed security flaws significantly impact the core functionality of the Serv-U application, enabling arbitrary native code execution with root privileges.

Among the most severe issues is a broken access control vulnerability that allows attackers with domain or group admin privileges to create a system admin user.

CVE CVSS Affected Component Affected Versions Impact

CVE-2025-40538 9.1 (Critical) Serv-U Core (Access Control) Serv-U (unpatched versions) Admin creation and root code execution.

CVE-2025-40539 9.1 (Critical) Serv-U Web Interface Serv-U (unpatched versions) Type confusion enables root code execution.

The latest version, Serv-U 15.5.4, resolves four high-severity security flaws, each with a CVSS score of 9.1.
Benjamin Scott · Thehackingpost

CVE-2025-40540 9.1 (Critical) Serv-U Web Interface Serv-U (unpatched versions) Type confusion enables root code execution.

CVE-2025-40541 9.1 (Critical) Serv-U API / Object Handling Serv-U (unpatched versions) IDOR flaw allows root code execution.

Once this unauthorized system-admin account is established, the attacker can execute malicious commands with root privileges.

Additionally, the software has two distinct type confusion vulnerabilities. These memory corruption flaws provide a direct pathway for an attacker to execute unauthorized native code as root.

The update also addresses an Insecure Direct Object Reference vulnerability, allowing attackers to bypass authorization mechanisms by directly accessing internal objects, resulting in remote code execution with root privileges.

These vulnerabilities could enable threat actors to deploy ransomware, steal sensitive enterprise data, or establish persistent backdoors within corporate networks .

SolarWinds has credited security researchers for responsibly disclosing these issues and collaborating with their engineering teams to develop effective patches.

Advertisement

Product Enhancements and Update Recommendations

Alongside these critical security patches, Serv-U version 15.5.4 introduces several functional improvements and platform support updates.

The application now officially supports Ubuntu 24.04 LTS, enhancing deployment flexibility in enterprise environments.

SolarWinds has reintroduced the download history feature in File Share , aligning it with legacy web client capabilities. Additionally, the file share interface now includes a precise time display next to the last modified date.

To further secure the application against modern web threats, SolarWinds implemented strict content security policy configurations.

The legacy login page now utilizes specific directives to prevent malicious embedding in other websites, neutralizing potential clickjacking attacks .

Administrators using previous versions of Serv-U should consult the end-of-life schedule , as earlier versions, such as 15.5.1, reached the end of engineering support by February 18, 2026.

Organizations must download the latest installation files from the customer portal to ensure their infrastructure remains secure against these critical remote code execution threats.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories