The Cyber Security Hub™[verified]@TheCyberSecHubDisclosure
SolarWinds Serv-U is affected by four critical RCE vulnerabilities (CVE-2025-40538 to CVE-2025-40541).
GovCERT.CZ[verified]@GOVCERT_CZPatch
SolarWinds Serv‑U is affected by a series of RCE vulnerabilities (CVE‑2025‑40538‑40541) that allow attackers to execute code as root; updating to version 15.5.4 or newer mitigates the risk.
Dr. John D. Johnson[verified]@johndjohnsonPatch
Four SolarWinds bugs (CVE‑2025‑40538‑41) are rated 9.1 CVSS and can lead to RCE; the post urges immediate patching, but provides no exploit or PoC details.
CVETodo[verified]@CveTodoDisclosure
The post announces CVE‑2025‑40541 as an IDOR flaw in Serv‑U, describing its nature but providing no PoC, exploit, patch, or evidence of active exploitation.
セキュリティ対策Lab[verified]@securityLab_jpPatch
SolarWinds Serv-U has released fixes for four critical vulnerabilities (CVE-2025-40538 to 40541).
ThreatSynop[verified]@ThreatSynopPatch
SolarWinds released Serv-U 15.5.4 to address four critical CVEs (CVE-2025-40538 to CVE-2025-40541) that enable remote code execution via broken access control, type confusion, and IDOR, with a patch now available.
The AI generalist[verified]@AIengineerlifeDisclosure
The post announces a critical IDOR vulnerability in SolarWinds Serv‑U that allows privileged code execution, but it does not provide PoC, exploit, or patch details.
ThreatSynop[verified]@ThreatSynopPatch
SolarWinds released Serv‑U v15.5.4 to patch four critical CVEs (CVE‑2025‑40538 to 40541) that enable root‑level compromise; organizations running internet‑facing Serv‑U should apply the patch immediately to mitigate ransomware, data theft, and backdoor risks.