CVE-2025-40538Patch(solarwinds / serv-u)

MEDIUMCVSS 7.2 · HIGH

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch solarwinds serv-u systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • serv-u

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 32 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 28 signals
  • Disclosure: 11 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 15 mentions (2026-02-25); latest day: 1
  • 32 total mentions across 7 days

Affected systems

Vendors
Products
serv-u

Deep dive

Activity timeline32 mentions / 7d
0481115Mentions · 2026-02-24: 10Mentions · 2026-02-25: 15Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-04: 1Active Exploitation · 2026-02-25: 1Patch / Workaround · 2026-02-24: 5Patch / Workaround · 2026-02-25: 11Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-02-24: 9Technical Details · 2026-02-25: 14Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-04: 102-2402-2502-2602-2702-2803-0103-04
Signal classification4 categories
Patch
1856.3%
Disclosure
1134.4%
General
26.3%
Active Exploitation
13.1%
Referenced assets47 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-2410
Disclosure5Patch5
2026-02-2515
Active Exploitation1Disclosure4Patch10
2026-02-262
General1Patch1
2026-02-272
Disclosure1Patch1
2026-02-281
Disclosure1
2026-03-011
General1
2026-03-041
Patch1
Full discourse20 posts
  • Defused@DefusedCyber
    Disclosure

    🚨 SolarWinds Serv-U just dropped 4 critical RCEs today (CVE-2025-40538/39/40/41, CVSS 9.1) - all leading to RCE No POC as of yet - We've added a Serv-U honeypot stream to catch exploitation attempts in the wild 🍯 https://console.defusedcyber.com/signup https://t.co/vV5Xt7vfar

    Post summary

    SolarWinds Serv-U disclosed four critical RCE vulnerabilities (CVE-2025-40538/39/40/41) with CVSS 9.1, but no PoC or exploit code has been shared yet; a honeypot is set up to detect potential exploitation attempts.

    2182541213.8K
    6.0K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    【いつもの】ファイル転送製品SolarWinds Serv-Uで重大(Critical)な脆弱性4件が修正。CVE-2025-40538~40541はいずれもCVSSスコア9.1で、root権限での任意コード実行。修正版提供あり。普段のように緊急パッチ適用を。 https://securityonline.info/root-access-granted-four-critical-rce-flaws-patched-in-solarwinds-serv-u/

    Post summary

    Four critical CVEs (CVE-2025-40538 to 40541) in SolarWinds Serv‑U have been patched; they allow root‑privilege arbitrary code execution with a CVSS score of 9.1, and the patch is available for immediate deployment.

    010821.5K
    7.2K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: 4 critical vulnerabilities in #SolarWinds Serv-U. CVE-2025-40538, CVE-2025-40539, CVE-2025-40540 and CVE-2025-40541 share the same CVSS score of 9.1. Threat actors could exploit either to achieve remote code execution. #RCE! https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-solarwinds-serv-u-servers-can-be-exploited-remote-code #Patch #Patch #Patch

    Post summary

    Four critical SolarWinds Serv‑U CVEs (CVE‑2025‑40538‑41) with a CVSS score of 9.1 enable remote code execution; the advisory urges immediate patching.

    03040362
    7.2K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Disclosure

    SolarWinds Serv-U hit by four critical RCE-level vulnerabilities https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces that SolarWinds Serv-U has four critical RCE-level vulnerabilities, but offers no further technical or exploitation details.

    01041464
    193.3K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨Upozorňujeme na sérii RCE zranitelností v SolarWinds Serv-U. CVE-2025-40538: Chyba zabezpečení v oblasti řízení přístupu, která při zneužití umožňuje útočníkovi vytvořit uživatele se systémovými oprávněními a spustit libovolný kód jako root pomocí oprávnění správce domény nebo správce skupiny. CVE-2025-40539: Chyba typu „type confusion“, která při zneužití umožňuje útočníkovi spustit libovolný nativní kód jako root. CVE-2025-40540: Chyba typu „type confusion“, která při zneužití umožňuje útočníkovi spustit libovolný nativní kód jako root. CVE-2025-40541: Zranitelnost typu IDOR (Insecure Direct Object Reference), která útočníkovi umožňuje spustit nativní kód jako root. K úspěšnému zneužití těchto zranitelností je potřeba účet s administrátorským oprávněním. 📌 Doporučujeme aktualizovat na verzi 15.5.4 či novější.

    Post summary

    SolarWinds Serv‑U hosts a series of RCE vulnerabilities (CVE‑2025‑40538‑40541) that enable root execution; updating to version 15.5.4 or newer mitigates the risk.

    01020776
    4.2K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Patch

    Patch these 4 critical, make-me-root SolarWinds bugs ASAP The four flaws, all of which earned a 9.1 CVSS rating, include a broken access control vulnerability (CVE-2025-40538), two type confusion bugs (CVE-2025-40540 and CVE-2025-40539), and an Insecure Direct Object Reference (IDOR) issue (CVE-2025-40541), all of which can lead to remote code execution (RCE). https://nuel.ink/5bzFZF

    Post summary

    The post announces four critical SolarWinds CVEs with high severity, details their types and RCE potential, and urges immediate patching.

    0101083
    1.1K followersView on X
  • Clone Systems@CloneSystemsInc
    Patch

    Vulnerability Alert — SolarWinds Serv-U SolarWinds patched 4 critical Serv-U 15.5 flaws (CVSS 9.1) that can lead to root code execution (CVE-2025-40538/39/40/41). Exploitation needs admin access, but Serv-U has a history of abuse. Upgrade to 15.5.4 now. #CyberSecurity https://t.co/4Sn8eYRU6b

    Post summary

    SolarWinds has released a patch for four critical Serv‑U 15.5 vulnerabilities (CVE‑2025‑40538/39/40/41) that could allow root code execution; users should upgrade to version 15.5.4 immediately.

    0002062
    247 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-40538 Serv-U Privilege Escalation via Broken Access Control Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-40538

    Post summary

    The text announces a Serv-U privilege escalation vulnerability (CVE-2025-40538) caused by broken access control, as reported on Vulmon.

    0001159
    4.0K followersView on X
  • iototsecnews@iototsecnews
    Patch

    SolarWinds Serv-U の脆弱性 CVE-2025-40538/40539/40540/40541 が FIX:root での RCE https://iototsecnews.jp/2026/02/25/solarwinds-critical-serv-u-vulnerabilities-enables-root-access/ SolarWinds Serv-U ファイル・サーバーにおいて、脆弱性 CVE-2025-40538/40539/40540/40541 (CVSS:9.1) が修正されました。これらの脆弱性は、いずれも最終的に root 権限でのリモートコード実行 (RCE) につながるものであり、攻撃者に対してサーバ全体の完全な支配権を許す恐れがあります。 これらの脆弱性に対応する、最新版 Serv-U 15.5.4 を SolarWinds はリリースしています。このバージョンでは、セキュリティ強化の一環として厳格なコンテンツ・セキュリティ・ポリシー (CSP) が導入され、他サイトへのレガシー・ログイン・ページの埋め込みを防止することで、クリック・ジャッキング攻撃に対処しています。それと同時に、Ubuntu 24.04 LTSの正式サポートや、ファイル共有機能の改善など、利便性の向上も図られています。 #CVE202540538 #CVE202540539 #CVE202540540 #CVE202540541 #ServU #SolarWinds #Vulnerability

    Post summary

    SolarWinds Serv‑U vulnerabilities CVE‑2025‑40538‑41 have been fixed in Serv‑U 15.5.4, mitigating the root‑level RCE risk; no PoC, exploit, or active exploitation is reported.

    01000189
    483 followersView on X
  • Help Net Security@helpnetsecurity
    Disclosure

    SolarWinds Serv-U hit by four critical RCE-level vulnerabilities - https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/ - @solarwinds @orcasec #FileTransfer #FileSharing #Cybersecurity #CybersecurityNews

    Post summary

    SolarWinds Serv-U is affected by four critical RCE vulnerabilities (CVE-2025-40538 to CVE-2025-40541) as reported by HelpNetSecurity.

    00010319
    60.0K followersView on X
  • Machina Record@MachinaRecord
    Disclosure

    🚨SolarWinds Serv-Uに重大な脆弱性、サーバーへのrootアクセスが可能に(CVE-2025-40538、CVE-2025-40539他) 🇦🇪アラブ首長国連邦、「テロリスト」によるランサムウェア攻撃を阻止したと主張 〜サイバーアラート2月25日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44109/

    Post summary

    SolarWinds Serv‑U has a critical vulnerability (CVE‑2025‑40538, CVE‑2025‑40539, etc.) that allows root access to the server, but no PoC, exploit, patch, or active exploitation details are provided.

    00001188
    1.2K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-40538: CRITICAL] Critical access control vulnerability in Serv-U enables attackers to create admin user & run code as privileged accounts via domain or group admin privileges. Risk is medium on Win...#cve,CVE-2025-40538,#cybersecurity https://cvefind.com/CVE-2025-40538

    Post summary

    The post announces a critical access control vulnerability in Serv‑U that permits attackers to create admin users and execute code with privileged rights, but it provides no PoC, exploit, or patch details.

    0001072
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-40538** is a **broken access control** vulnerability in **Serv-U**, a managed file transfer server. When exploited, this flaw allows a malicious actor with **administrative privileges** to **create a system administrator user** and **execute arbitrary code** with **privileged (administrative) rights**. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation #AuthBypass https://cvetodo.com/cve/CVE-2025-40538

    Post summary

    The post announces CVE‑2025‑40538, a broken access control flaw in Serv‑U that allows an administrator to create a system administrator user and execute arbitrary code with elevated privileges.

    0001065
    20 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-40538 (CVSS:9.1, CRITICAL) is Analyzed. A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to crea..https://nvd.nist.gov/vuln/detail/CVE-2025-40538 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet references CVE‑2025‑40538, noting its critical CVSS score and broken access control in Serv‑U, but does not mention PoC, exploit code, active exploitation, or patches.

    0000073
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-40538 (CVSS:9.1, CRITICAL) is Analyzed. A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to crea..https://nvd.nist.gov/vuln/detail/CVE-2025-40538 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑40538, a critical broken access control flaw in Serv‑U that could give a malicious actor unrestricted access.

    0000092
    173 followersView on X
  • Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56
    Disclosure

    All four security defects, tracked as CVE-2025-40538 to CVE-2025-40541, have a CVSS score of 9.1, could result in remote code execution, and impact Serv-U version 15.5. https://www.securityweek.com/solarwinds-patches-four-critical-serv-u-vulnerabilities/

    Post summary

    Four high‑severity CVEs (CVE‑2025‑40538 to 40541) affecting Serv‑U 15.5 are disclosed with remote code execution potential; no PoC, exploit code, or active exploitation evidence is provided.

    0000028
    904 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos SolarWinds ❗ CVE-2025-40541 ❗ CVE-2025-40540 ❗ CVE-2025-40538 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-solarwinds-3/ https://t.co/DJ2o6YtpDk

    Post summary

    The post lists three SolarWinds CVEs and provides a link for further details, but offers no additional technical or exploit information.

    00000104
    6.6K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    SolarWinds Serv-Uが4件の重大な脆弱性を修正(CVE-2025-40538 / 40539 / 40540 / 40541) https://rocket-boys.co.jp/security-measures-lab/solarwinds-serv-u-fixes-four-critical-vulnerabilities-cve-2025-40538-cve-2025-40539-cve-2025-40540-cve-2025-40541/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    SolarWinds Serv-U has released fixes for four critical vulnerabilities (CVE-2025-40538 to 40541).

    00000115
    319 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Patches Four Critical Serv-U Vulnerabilities (CVE-2025-40538 to CVE-2025-40541) SolarWinds released Serv-U 15.5.4 to fix four critical (CVSS 9.1) flaws that could enable remote code execution, but exploitation requires an attacker to already have administrative privileges on the Serv-U instance. The bugs include broken access control, type confusion, and IDOR paths that can be abused to create a system admin and run code with elevated privileges. 🎯 Target: Global/Enterprise File Transfer Infrastructure #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://www.securityweek.com/solarwinds-patches-four-critical-serv-u-vulnerabilities/

    Post summary

    SolarWinds released Serv‑U 15.5.4 to address four critical CVEs (CVE‑2025‑40538 to CVE‑2025‑40541) that could enable remote code execution if administrative privileges exist, with detailed vulnerability types and a CVSS score of 9.1 provided.

    0000047
    214 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Serv-U 15.5.4 Patches 4 Critical Flaws Enabling Root-Level Compromise SolarWinds released Serv-U v15.5.4 to fix four critical vulnerabilities (CVE-2025-40538 to CVE-2025-40541, CVSS 9.1) that can let attackers with high privileges create unauthorized system admins and execute native code as root via access-control, type confusion, and IDOR issues. Organizations running internet-facing Serv-U should patch immediately to reduce full-compromise risk (ransomware, data theft, persistent backdoors). 🎯 Target: Global/Enterprise File Transfer Infrastructure #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cybersecuritynews.com/solarwinds-serv-u-vulnerabilities-2/

    Post summary

    SolarWinds released Serv‑U v15.5.4 to patch four critical CVEs (CVE‑2025‑40538 to 40541) with a CVSS score of 9.1, urging organizations to apply the update immediately to prevent root‑level compromise.

    0000032
    214 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsserv-u---

Explore more