CVE-2025-40540Patch(solarwinds / serv-u)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch solarwinds serv-u systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-704

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • serv-u

Threat summary

  • Patch or workaround signal is available
  • 15 mentions across 6 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 12 signals
  • Disclosure: 5 classified signals
  • General: 4 classified signals
  • Peaked 4d ago at 5 mentions (2026-02-25); latest day: 1
  • 15 total mentions across 6 days

Affected systems

Vendors
Products
serv-u

Deep dive

Activity timeline15 mentions / 6d
01345Mentions · 2026-02-24: 4Mentions · 2026-02-25: 5Mentions · 2026-02-26: 3Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Patch / Workaround · 2026-02-25: 4Patch / Workaround · 2026-02-26: 2Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-24: 4Technical Details · 2026-02-25: 4Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2502-2602-2702-2803-01
Signal classification3 categories
Patch
640.0%
Disclosure
533.3%
General
426.7%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-02-244
Disclosure3General1
2026-02-255
Disclosure1General1Patch3
2026-02-263
General1Patch2
2026-02-271
Patch1
2026-02-281
General1
2026-03-011
Disclosure1
Full discourse15 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: 4 critical vulnerabilities in #SolarWinds Serv-U. CVE-2025-40538, CVE-2025-40539, CVE-2025-40540 and CVE-2025-40541 share the same CVSS score of 9.1. Threat actors could exploit either to achieve remote code execution. #RCE! https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-solarwinds-serv-u-servers-can-be-exploited-remote-code #Patch #Patch #Patch

    Post summary

    Four critical SolarWinds Serv‑U CVEs (CVE‑2025‑40538‑40541) with a CVSS score of 9.1 are highlighted, warning of potential remote code execution and urging users to apply patches.

    03040362
    7.2K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨Upozorňujeme na sérii RCE zranitelností v SolarWinds Serv-U. CVE-2025-40538: Chyba zabezpečení v oblasti řízení přístupu, která při zneužití umožňuje útočníkovi vytvořit uživatele se systémovými oprávněními a spustit libovolný kód jako root pomocí oprávnění správce domény nebo správce skupiny. CVE-2025-40539: Chyba typu „type confusion“, která při zneužití umožňuje útočníkovi spustit libovolný nativní kód jako root. CVE-2025-40540: Chyba typu „type confusion“, která při zneužití umožňuje útočníkovi spustit libovolný nativní kód jako root. CVE-2025-40541: Zranitelnost typu IDOR (Insecure Direct Object Reference), která útočníkovi umožňuje spustit nativní kód jako root. K úspěšnému zneužití těchto zranitelností je potřeba účet s administrátorským oprávněním. 📌 Doporučujeme aktualizovat na verzi 15.5.4 či novější.

    Post summary

    SolarWinds Serv‑U is affected by a series of RCE vulnerabilities (CVE‑2025‑40538‑40541) that allow root execution; updating to version 15.5.4 or newer mitigates the risk.

    01020776
    4.2K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Patch

    Patch these 4 critical, make-me-root SolarWinds bugs ASAP The four flaws, all of which earned a 9.1 CVSS rating, include a broken access control vulnerability (CVE-2025-40538), two type confusion bugs (CVE-2025-40540 and CVE-2025-40539), and an Insecure Direct Object Reference (IDOR) issue (CVE-2025-40541), all of which can lead to remote code execution (RCE). https://nuel.ink/5bzFZF

    Post summary

    The post urges immediate patching of four SolarWinds CVEs rated 9.1 CVSS that allow remote code execution via broken access control, type confusion, and IDOR vulnerabilities.

    0101083
    1.1K followersView on X
  • Security Harvester@secharvesterx
    General

    SolarWinds CVE 9.1 - CVE-2025-4054 https://fixthecve.com/cve/CVE-2025-40540 https://t.co/HRN9PgjNo7

    Post summary

    The tweet references SolarWinds CVE-2025-4054 but provides no further details or actionable information.

    0001157
    427 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-40540 Type Confusion Vulnerability in Serv-U Enables Privileged... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-40540 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post references CVE-2025-40540, a type confusion vulnerability in Serv‑U, but provides no evidence of PoC, exploit, active use, or patch information.

    0000147
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-40540 (CVSS:9.1, CRITICAL) is Analyzed. A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb..https://nvd.nist.gov/vuln/detail/CVE-2025-40540 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑40540, a critical type‑confusion flaw in Serv‑U that permits arbitrary code execution, but it does not provide a PoC, exploit, or patch information.

    0000074
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-40540 (CVSS:9.1, CRITICAL) is Analyzed. A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb..https://nvd.nist.gov/vuln/detail/CVE-2025-40540 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post offers a high‑level overview of CVE‑2025‑40540, noting it as a type‑confusion flaw in Serv‑U with a critical CVSS score, but does not provide evidence of exploits, patches, or PoC details.

    0000092
    173 followersView on X
  • Security Harvester@secharvesterx
    Patch

    CVE-2025-40540 (CVSS 9.1) — SolarWinds Serv-U Critical Vulnerability (Type Confusion RCE) — Patch Released https://www.bleepingcomputer.com/news/security/critical-solarwinds-serv-u-flaws-offer-root-access-to-servers/ https://t.co/jV96QPZLO0

    Post summary

    SolarWinds Serv-U CVE-2025-40540 is a type confusion RCE with CVSS 9.1, and a patch has been released; no PoC, exploit code, or active exploitation claims are mentioned.

    0000058
    440 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos SolarWinds ❗ CVE-2025-40541 ❗ CVE-2025-40540 ❗ CVE-2025-40538 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-solarwinds-3/ https://t.co/DJ2o6YtpDk

    Post summary

    The post lists three CVE identifiers for SolarWinds products and provides a link for more information, but no further details are given.

    00000104
    6.6K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    SolarWinds Serv-Uが4件の重大な脆弱性を修正(CVE-2025-40538 / 40539 / 40540 / 40541) https://rocket-boys.co.jp/security-measures-lab/solarwinds-serv-u-fixes-four-critical-vulnerabilities-cve-2025-40538-cve-2025-40539-cve-2025-40540-cve-2025-40541/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    SolarWinds Serv‑U has released fixes for four critical CVEs (CVE‑2025‑40538 to 40541); the post does not provide PoC, exploit, or technical details beyond the CVE IDs.

    00000115
    319 followersView on X
  • cybersecuritypath@cybrsecpath
    Patch

    https://cybersecuritypath.com/cve-2025-40540-solarwinds-serv-u-security-vulnerability-alert/

    Post summary

    The post reports a critical CVE‑2025‑40540 in SolarWinds Serv‑U, provides technical details and a vendor patch, and does not mention active exploitation or a PoC.

    000006
  • SecAlerts@SecAlertsCo
    Patch

    Patches for 4 CVSS 9.1 #Solarwinds vulns. Info at SecAlerts: CVE-2025-40538: https://secalerts.co/vulnerability/CVE-2025-40538 CVE-2025-40539: https://secalerts.co/vulnerability/CVE-2025-40539 CVE-2025-40540: https://secalerts.co/vulnerability/CVE-2025-40540 CVE-2025-40541: https://secalerts.co/vulnerability/CVE-2025-40541 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp https://t.co/UMGDgMHeOT

    Post summary

    The tweet announces patches for four high‑severity SolarWinds vulnerabilities (CVE‑2025‑40538 to CVE‑2025‑40541) and directs readers to SecAlerts for details.

    0000094
    798 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-40540 A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. Thi… https://www.cve.org/CVERecord?id=CVE-2025-40540

    Post summary

    The text outlines a type‑confusion flaw in Serv‑U that permits privileged native code execution, but it does not mention any PoC, exploit, patch, or active exploitation.

    00000128
    56.5K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-40540** is a **type confusion vulnerability** in **Serv-U**, a managed file transfer server software. When exploited, this flaw allows a malicious actor to execute **arbitrary native code** with **privileged account** privileges. The attack requires **administrative privileges** to exploit, which limits the attack surface but still poses a significant risk if an attacker gains such privileges. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2025-40540

    Post summary

    The post discloses CVE‑2025‑40540 as a type‑confusion flaw in Serv‑U that permits privileged code execution when administrative rights are present, but it does not mention any PoC, exploit, or patch.

    0000045
    20 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-40540: CRITICAL] Type confusion vulnerability in Serv-U allows a malicious actor to run native code as a privileged account, requiring administrative privileges to exploit. Risk is medium on Window...#cve,CVE-2025-40540,#cybersecurity https://cvefind.com/CVE-2025-40540

    Post summary

    The post announces a type‑confusion vulnerability (CVE‑2025‑40540) in Serv‑U that permits privileged code execution, but it does not provide a PoC, exploit, or patch information.

    0000071
    584 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsserv-u---

Explore more