logo

SolarWinds patches four critical Serv-U flaws enabling root access

ID: 72b1f209-3009-5df6-9c77-d369a830814b

STIX ID: report--72b1f209-3009-5df6-9c77-d369a830814b

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-02-24

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

SolarWinds issued updates to fix four critical Serv-U vulnerabilities—including a broken access control issue, two type confusion flaws, and an IDOR (CVEs 2025-40538, 2025-40540, 2025-40539, 2025-40541)—all rated CVSS 9.1 and capable of enabling remote code execution and full root compromise on unpatched servers; administrators should apply the patches promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.