SolarWinds released Serv-U 15.5.4 security updates addressing four remote code execution vulnerabilities that can allow execution of arbitrary code as a privileged (root/admin) account on affected Windows and Linux servers. The most severe issue, CVE-2025-40538, is a broken access control flaw that can let an attacker with domain admin or group admin privileges create a system admin user and then execute code with elevated permissions; it is scored CVSS:3.1 AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H and mapped to CWE-269.
SolarWinds also fixed CVE-2025-40539 and CVE-2025-40540 (both type confusion issues, CWE-704) and CVE-2025-40541 (an IDOR issue leading to privileged code execution). All four vulnerabilities require high/administrative privileges to exploit, which limits standalone exploitation but supports chaining scenarios (e.g., stolen admin credentials or prior privilege escalation). Internet exposure remains a concern: one report cited Shodan identifying 12,000+ exposed Serv-U instances, while Shadowserver estimated <1,200.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Belgium's Centre for Cybersecurity published a warning that critical SolarWinds Serv-U server vulnerabilities could be exploited for remote code execution and urged immediate patching. The notice amplified the vendor's remediation guidance following the disclosure.
The Canadian Centre for Cyber Security published advisory AV26-165 highlighting SolarWinds' Serv-U vulnerabilities, especially CVE-2025-40538, and urged administrators to review the vendor guidance and apply updates. The advisory covered critical issues affecting versions before 15.5.4.
In its disclosure of the four Serv-U vulnerabilities, SolarWinds stated it had not observed exploitation of these newly disclosed flaws in the wild. Multiple reports also noted the issues were not listed in CISA's KEV catalog at the time of disclosure.
SolarWinds published Serv-U version 15.5.4 and associated security advisories to fix four critical vulnerabilities affecting versions prior to 15.5.4. The flaws can enable creation of a system administrator account or arbitrary native code execution with elevated privileges, though exploitation requires administrative access.
SolarWinds PSIRT recorded four critical Serv-U vulnerabilities—CVE-2025-40538, CVE-2025-40539, CVE-2025-40540, and CVE-2025-40541. The CVE records indicate the issues were received on this date and involve broken access control, type confusion, and IDOR flaws that can lead to privileged code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
secpod.com
Open sourcesocradar.io
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourcego.theregister.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.