CVE-2025-40539Disclosure(solarwinds / serv-u)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch solarwinds serv-u systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-704

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • serv-u

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 11 signals
  • Disclosure: 8 classified signals
  • Peaked 5d ago at 4 mentions (2026-02-24); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
serv-u

Deep dive

Activity timeline12 mentions / 6d
01234Mentions · 2026-02-24: 4Mentions · 2026-02-25: 4Mentions · 2026-02-26: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1PoC Mentioned / Linked · 2026-02-25: 1Patch / Workaround · 2026-02-25: 4Technical Details · 2026-02-24: 4Technical Details · 2026-02-25: 4Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2502-2602-2702-2803-01
Signal classification2 categories
Disclosure
866.7%
Patch
433.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-02-244
Disclosure4
2026-02-254
Disclosure1Patch3
2026-02-261
Patch1
2026-02-271
Disclosure1
2026-02-281
Disclosure1
2026-03-011
Disclosure1
Full discourse12 posts
  • CCB Alert@CCBalert
    Patch

    Warning: 4 critical vulnerabilities in #SolarWinds Serv-U. CVE-2025-40538, CVE-2025-40539, CVE-2025-40540 and CVE-2025-40541 share the same CVSS score of 9.1. Threat actors could exploit either to achieve remote code execution. #RCE! https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-solarwinds-serv-u-servers-can-be-exploited-remote-code #Patch #Patch #Patch

    Post summary

    The advisory highlights four critical RCE vulnerabilities in SolarWinds Serv‑U with CVSS 9.1 and urges users to apply the available patch.

    03040362
    7.2K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Disclosure

    🚨Upozorňujeme na sérii RCE zranitelností v SolarWinds Serv-U. CVE-2025-40538: Chyba zabezpečení v oblasti řízení přístupu, která při zneužití umožňuje útočníkovi vytvořit uživatele se systémovými oprávněními a spustit libovolný kód jako root pomocí oprávnění správce domény nebo správce skupiny. CVE-2025-40539: Chyba typu „type confusion“, která při zneužití umožňuje útočníkovi spustit libovolný nativní kód jako root. CVE-2025-40540: Chyba typu „type confusion“, která při zneužití umožňuje útočníkovi spustit libovolný nativní kód jako root. CVE-2025-40541: Zranitelnost typu IDOR (Insecure Direct Object Reference), která útočníkovi umožňuje spustit nativní kód jako root. K úspěšnému zneužití těchto zranitelností je potřeba účet s administrátorským oprávněním. 📌 Doporučujeme aktualizovat na verzi 15.5.4 či novější.

    Post summary

    SolarWinds Serv‑U is affected by a series of RCE vulnerabilities (CVE‑2025‑40538‑40541) that allow root execution; updating to version 15.5.4 or newer is recommended.

    01020776
    4.2K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Disclosure

    Patch these 4 critical, make-me-root SolarWinds bugs ASAP The four flaws, all of which earned a 9.1 CVSS rating, include a broken access control vulnerability (CVE-2025-40538), two type confusion bugs (CVE-2025-40540 and CVE-2025-40539), and an Insecure Direct Object Reference (IDOR) issue (CVE-2025-40541), all of which can lead to remote code execution (RCE). https://nuel.ink/5bzFZF

    Post summary

    Four newly disclosed SolarWinds CVEs with CVSS 9.1 that enable remote code execution are highlighted, and the post urges immediate patching.

    0101083
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-40539 Type Confusion Vulnerability in Serv-U Enables Privileged Native Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-40539

    Post summary

    A type confusion vulnerability in Serv‑U (CVE‑2025‑40539) allows privileged native code execution.

    0001143
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-40539 (CVSS:9.1, CRITICAL) is Analyzed. A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb..https://nvd.nist.gov/vuln/detail/CVE-2025-40539 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE‑2025‑40539, noting a type‑confusion flaw in Serv‑U with a CVSS score of 9.1 that could allow arbitrary code execution, but provides no PoC, exploit, or patch information.

    0000074
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-40539 (CVSS:9.1, CRITICAL) is Analyzed. A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb..https://nvd.nist.gov/vuln/detail/CVE-2025-40539 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical type‑confusion flaw in Serv‑U (CVE‑2025‑40539) with a high CVSS score, but provides no evidence of exploitation, patches, or PoC details.

    0000093
    173 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    SolarWinds Serv-Uが4件の重大な脆弱性を修正(CVE-2025-40538 / 40539 / 40540 / 40541) https://rocket-boys.co.jp/security-measures-lab/solarwinds-serv-u-fixes-four-critical-vulnerabilities-cve-2025-40538-cve-2025-40539-cve-2025-40540-cve-2025-40541/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    SolarWinds Serv-U has released fixes for four critical vulnerabilities (CVE-2025-40538 to 40541).

    00000115
    319 followersView on X
  • cybersecuritypath@cybrsecpath
    Patch

    https://cybersecuritypath.com/solarwinds-serv-u-type-confusion-flaw-enables-rce-cve-2025-40539/

    Post summary

    SolarWinds Serv‑U is affected by a type‑confusion flaw (CVE‑2025‑40539) that permits remote code execution; a patch is available, technical details are disclosed, but no active exploitation or PoC is confirmed.

    000005
  • SecAlerts@SecAlertsCo
    Patch

    Patches for 4 CVSS 9.1 #Solarwinds vulns. Info at SecAlerts: CVE-2025-40538: https://secalerts.co/vulnerability/CVE-2025-40538 CVE-2025-40539: https://secalerts.co/vulnerability/CVE-2025-40539 CVE-2025-40540: https://secalerts.co/vulnerability/CVE-2025-40540 CVE-2025-40541: https://secalerts.co/vulnerability/CVE-2025-40541 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp https://t.co/UMGDgMHeOT

    Post summary

    The tweet announces that patches are available for four high‑severity SolarWinds vulnerabilities (CVSS 9.1) and provides links to vendor advisories.

    0000094
    798 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-40539 A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. Thi… https://www.cve.org/CVERecord?id=CVE-2025-40539

    Post summary

    The text announces CVE‑2025‑40539, a type‑confusion flaw in Serv‑U that permits attackers to run arbitrary native code with privileged rights.

    00000128
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-40539: CRITICAL] Type confusion vulnerability in Serv-U allows executing arbitrary code as privileged account. Needs admin privileges to exploit. Medium risk on Windows due to default less-privileg...#cve,CVE-2025-40539,#cybersecurity https://cvefind.com/CVE-2025-40539

    Post summary

    The post announces a critical type‑confusion flaw in Serv‑U that permits privileged code execution, requiring admin rights, and notes a medium risk on Windows.

    0000071
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2025-40539 is a **type confusion vulnerability** found in Serv-U, a popular file transfer server software. When exploited, this flaw allows a malicious actor to execute arbitrary native code with the privileges of the compromised service, which can lead to full system compromise. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation #Microsoft https://cvetodo.com/cve/CVE-2025-40539

    Post summary

    The post announces CVE‑2025‑40539 as a type‑confusion flaw in Serv‑U that can lead to remote code execution and full system compromise, but provides no PoC, exploit, or patch details.

    0000049
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsserv-u---

Explore more