kokumօtօ[verified]@__kokumotoPatch
Four critical CVEs (CVE-2025-40538 to 40541) in SolarWinds Serv‑U have been patched; they allow root‑privilege arbitrary code execution with a CVSS score of 9.1, and the patch is available for immediate deployment.
The Cyber Security Hub™[verified]@TheCyberSecHubDisclosure
The tweet announces that SolarWinds Serv-U has four critical RCE-level vulnerabilities, but offers no further technical or exploitation details.
GovCERT.CZ[verified]@GOVCERT_CZPatch
SolarWinds Serv‑U hosts a series of RCE vulnerabilities (CVE‑2025‑40538‑40541) that enable root execution; updating to version 15.5.4 or newer mitigates the risk.
Dr. John D. Johnson[verified]@johndjohnsonPatch
The post announces four critical SolarWinds CVEs with high severity, details their types and RCE potential, and urges immediate patching.
Machina Record[verified]@MachinaRecordDisclosure
SolarWinds Serv‑U has a critical vulnerability (CVE‑2025‑40538, CVE‑2025‑40539, etc.) that allows root access to the server, but no PoC, exploit, patch, or active exploitation details are provided.
CVETodo[verified]@CveTodoDisclosure
The post announces CVE‑2025‑40538, a broken access control flaw in Serv‑U that allows an administrator to create a system administrator user and execute arbitrary code with elevated privileges.
セキュリティ対策Lab[verified]@securityLab_jpPatch
SolarWinds Serv-U has released fixes for four critical vulnerabilities (CVE-2025-40538 to 40541).
ThreatSynop[verified]@ThreatSynopPatch
SolarWinds released Serv‑U 15.5.4 to address four critical CVEs (CVE‑2025‑40538 to CVE‑2025‑40541) that could enable remote code execution if administrative privileges exist, with detailed vulnerability types and a CVSS score of 9.1 provided.