logo

SolarWinds Serv-U 15.5.4 Fixes Four Privileged RCE Vulnerabilities

ID: c943f631-5939-5f73-a4c4-29ddabcdd6cd

STIX ID: report--c943f631-5939-5f73-a4c4-29ddabcdd6cd

Feed Name: SOCRadar Blog

Threat Score
70/100

Date Published: 2026-02-25

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

SolarWinds released Serv-U 15.5.4 to fix four critical CVEs (CVSS 9.1) in Serv-U 15.5 — including improper privilege management (allows creation of admin accounts), two type confusion flaws, and an IDOR — that let an attacker with administrative access execute native code at privileged/root level; organizations should upgrade immediately, restrict and monitor administrative access, enable MFA, hunt for suspicious admin activity, rotate credentials if compromise is suspected, and verify patches because no active exploitation was reported but the potential impact is high.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.