logo

SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution

ID: 53ee0b68-21ae-5658-b0e6-a530409fee88

STIX ID: report--53ee0b68-21ae-5658-b0e6-a530409fee88

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-02-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

SolarWinds Serv-U 15.5 contains four critical RCE vulnerabilities (CVE-2025-40538–40541) — including broken access control, type confusion, and an IDOR — that can enable creation of admin users and execution of native code as root. Patches are available in Serv-U 15.5.4; exploitation requires administrative privileges and SolarWinds reports no observed active exploitation, although prior Serv-U vulnerabilities have been exploited by groups like Storm-0322.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.