SolarWinds Serv-U has been found to contain two critical vulnerabilities, CVE-2025-40548 and CVE-2025-40549, both with a CVSS score of 9.1. These flaws allow authenticated administrators to perform remote code execution and bypass path restrictions, potentially enabling attackers with admin access to execute arbitrary code or access restricted directories. The vulnerabilities are particularly severe on non-Windows deployments, where default service account privileges may not mitigate the risk. Both issues require administrative privileges to exploit, but their impact is considered critical due to the potential for full system compromise.
Security advisories highlight that the vulnerabilities stem from missing validation processes and improper path restriction enforcement within the Serv-U software. While the flaws are not exploitable by unauthenticated users, organizations using SolarWinds Serv-U are urged to review their deployments, especially where admin credentials may be exposed or weakly protected. No specific affected product versions have been listed, but the vulnerabilities have been confirmed by SolarWinds and are publicly documented in multiple security feeds.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Later reporting stated that SolarWinds had addressed three critical vulnerabilities in Serv-U. This marked the vendor response and remediation stage for the disclosed Serv-U security issues.
Subsequent reporting described the SolarWinds Serv-U issues as critical flaws with a CVSS score of 9.1, noting that an authenticated administrator could achieve remote code execution and bypass path restrictions. This added technical characterization of the impact of the disclosed vulnerabilities.
SolarWinds Serv-U vulnerabilities CVE-2025-40548 and CVE-2025-40549 were publicly listed as high-severity issues. The flaws were described as a broken access control remote code execution vulnerability and a path restriction bypass vulnerability affecting Serv-U.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.