CVE-2025-40541Patch(solarwinds / serv-u)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch solarwinds serv-u systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-704CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • serv-u

Threat summary

  • Patch or workaround signal is available
  • 24 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 21 signals
  • Disclosure: 10 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 13 mentions (2026-02-25); latest day: 1
  • 24 total mentions across 7 days

Affected systems

Vendors
Products
serv-u

Deep dive

Activity timeline24 mentions / 7d
0371013Mentions · 2026-02-24: 4Mentions · 2026-02-25: 13Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-25: 8Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-02-27: 2Patch / Workaround · 2026-03-03: 1Technical Details · 2026-02-24: 4Technical Details · 2026-02-25: 12Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-03: 102-2402-2502-2602-2702-2803-0103-03
Signal classification3 categories
Patch
1250.0%
Disclosure
1041.7%
General
28.3%
Referenced assets25 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-244
Disclosure4
2026-02-2513
Disclosure3General2Patch8
2026-02-262
Disclosure1Patch1
2026-02-272
Patch2
2026-02-281
Disclosure1
2026-03-011
Disclosure1
2026-03-031
Patch1
Full discourse20 posts
  • Wazuh@wazuh
    Patch

    SolarWinds Serv-U 15.5.3 and earlier are affected by critical IDOR CVE-2025-40541 (CVSS 9.1). Update to 15.5.4 or later immediately, restrict access to trusted networks, and monitor logs for suspicious activity. Read more: https://ow.ly/3RwQ50Yoltn https://t.co/8WmkjjvOfc

    Post summary

    SolarWinds Serv-U versions 15.5.3 and earlier are vulnerable to CVE-2025-40541; users should upgrade to 15.5.4 or later and apply network restrictions and monitoring.

    0100132700
    7.8K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: 4 critical vulnerabilities in #SolarWinds Serv-U. CVE-2025-40538, CVE-2025-40539, CVE-2025-40540 and CVE-2025-40541 share the same CVSS score of 9.1. Threat actors could exploit either to achieve remote code execution. #RCE! https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-solarwinds-serv-u-servers-can-be-exploited-remote-code #Patch #Patch #Patch

    Post summary

    Four critical SolarWinds Serv‑U vulnerabilities (CVE‑2025‑40538 to 40541) with a CVSS score of 9.1 enable remote code execution; patches are available via the linked advisory.

    03040362
    7.2K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Disclosure

    SolarWinds Serv-U hit by four critical RCE-level vulnerabilities https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    SolarWinds Serv-U is affected by four critical RCE vulnerabilities (CVE-2025-40538 to CVE-2025-40541).

    01041464
    193.3K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨Upozorňujeme na sérii RCE zranitelností v SolarWinds Serv-U. CVE-2025-40538: Chyba zabezpečení v oblasti řízení přístupu, která při zneužití umožňuje útočníkovi vytvořit uživatele se systémovými oprávněními a spustit libovolný kód jako root pomocí oprávnění správce domény nebo správce skupiny. CVE-2025-40539: Chyba typu „type confusion“, která při zneužití umožňuje útočníkovi spustit libovolný nativní kód jako root. CVE-2025-40540: Chyba typu „type confusion“, která při zneužití umožňuje útočníkovi spustit libovolný nativní kód jako root. CVE-2025-40541: Zranitelnost typu IDOR (Insecure Direct Object Reference), která útočníkovi umožňuje spustit nativní kód jako root. K úspěšnému zneužití těchto zranitelností je potřeba účet s administrátorským oprávněním. 📌 Doporučujeme aktualizovat na verzi 15.5.4 či novější.

    Post summary

    SolarWinds Serv‑U is affected by a series of RCE vulnerabilities (CVE‑2025‑40538‑40541) that allow attackers to execute code as root; updating to version 15.5.4 or newer mitigates the risk.

    01020776
    4.2K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Patch

    Patch these 4 critical, make-me-root SolarWinds bugs ASAP The four flaws, all of which earned a 9.1 CVSS rating, include a broken access control vulnerability (CVE-2025-40538), two type confusion bugs (CVE-2025-40540 and CVE-2025-40539), and an Insecure Direct Object Reference (IDOR) issue (CVE-2025-40541), all of which can lead to remote code execution (RCE). https://nuel.ink/5bzFZF

    Post summary

    Four SolarWinds bugs (CVE‑2025‑40538‑41) are rated 9.1 CVSS and can lead to RCE; the post urges immediate patching, but provides no exploit or PoC details.

    0101083
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-40541 Serv-U IDOR Vulnerability Enables Privileged Native Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-40541

    Post summary

    Serv‑U IDOR vulnerability (CVE‑2025‑40541) allows privileged native code execution; no PoC, exploit, patch, or active exploitation details are provided.

    0001163
    4.0K followersView on X
  • Help Net Security@helpnetsecurity
    Disclosure

    SolarWinds Serv-U hit by four critical RCE-level vulnerabilities - https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/ - @solarwinds @orcasec #FileTransfer #FileSharing #Cybersecurity #CybersecurityNews

    Post summary

    SolarWinds Serv-U is reported to have four critical RCE vulnerabilities (CVE-2025-40538 to CVE-2025-40541) according to a HelpNetSecurity article.

    00010319
    60.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-40541: CRITICAL] In Serv-U, an Insecure Direct Object Reference (IDOR) vulnerability allows executing native code with admin privileges, posing a medium risk particularly on Windows systems.#cve,CVE-2025-40541,#cybersecurity https://cvefind.com/CVE-2025-40541

    Post summary

    Serv‑U IDOR vulnerability (CVE‑2025‑40541) permits native code execution with admin privileges on Windows, classified as critical but assessed as medium risk.

    0001070
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-40541** pertains to an **Insecure Direct Object Reference (IDOR)** vulnerability found in **Serv-U**, a managed file transfer server. An IDOR vulnerability allows an attacker to access or manipulate objects (such as files, data, or functions) directly by manipulating parameters or identifiers without proper authorization checks. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation #Microsoft https://cvetodo.com/cve/CVE-2025-40541

    Post summary

    The post announces CVE‑2025‑40541 as an IDOR flaw in Serv‑U, describing its nature but providing no PoC, exploit, patch, or evidence of active exploitation.

    0001057
    20 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-40541 (CVSS:9.1, CRITICAL) is Analyzed. An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor..https://nvd.nist.gov/vuln/detail/CVE-2025-40541 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical IDOR vulnerability in Serv‑U (CVE‑2025‑40541) with CVSS 9.1, but does not mention exploitation, patches, or PoC.

    0000073
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-40541 (CVSS:9.1, CRITICAL) is Analyzed. An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor..https://nvd.nist.gov/vuln/detail/CVE-2025-40541 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces a critical IDOR vulnerability in Serv-U (CVE-2025-40541) with a CVSS score of 9.1, but offers no PoC, exploit code, or patch information.

    0000091
    173 followersView on X
  • Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56
    Patch

    All four security defects, tracked as CVE-2025-40538 to CVE-2025-40541, have a CVSS score of 9.1, could result in remote code execution, and impact Serv-U version 15.5. https://www.securityweek.com/solarwinds-patches-four-critical-serv-u-vulnerabilities/

    Post summary

    SolarWinds has issued patches for four critical Serv‑U vulnerabilities (CVE‑2025‑40538 to 40541) that could lead to remote code execution, with a CVSS score of 9.1 and affecting version 15.5.

    0000028
    904 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos SolarWinds ❗ CVE-2025-40541 ❗ CVE-2025-40540 ❗ CVE-2025-40538 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-solarwinds-3/ https://t.co/DJ2o6YtpDk

    Post summary

    The post lists three CVE identifiers for SolarWinds products and directs readers to a link for more information.

    00000104
    6.6K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    SolarWinds Serv-Uが4件の重大な脆弱性を修正(CVE-2025-40538 / 40539 / 40540 / 40541) https://rocket-boys.co.jp/security-measures-lab/solarwinds-serv-u-fixes-four-critical-vulnerabilities-cve-2025-40538-cve-2025-40539-cve-2025-40540-cve-2025-40541/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    SolarWinds Serv-U has released fixes for four critical vulnerabilities (CVE-2025-40538 to 40541).

    00000115
    319 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Patches Four Critical Serv-U Vulnerabilities (CVE-2025-40538 to CVE-2025-40541) SolarWinds released Serv-U 15.5.4 to fix four critical (CVSS 9.1) flaws that could enable remote code execution, but exploitation requires an attacker to already have administrative privileges on the Serv-U instance. The bugs include broken access control, type confusion, and IDOR paths that can be abused to create a system admin and run code with elevated privileges. 🎯 Target: Global/Enterprise File Transfer Infrastructure #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://www.securityweek.com/solarwinds-patches-four-critical-serv-u-vulnerabilities/

    Post summary

    SolarWinds released Serv-U 15.5.4 to address four critical CVEs (CVE-2025-40538 to CVE-2025-40541) that enable remote code execution via broken access control, type confusion, and IDOR, with a patch now available.

    0000047
    214 followersView on X
  • The AI generalist@AIengineerlife
    Disclosure

    🚨 CVE-2025-40541 - CRITICAL SolarWinds Serv-U 🤖 AI Summary: Critical IDOR flaw in SolarWinds Serv-U enables privileged code execution. Requires admin access but poses severe risk to compr... ThreatScore: 91/100 🔗 http://threatmonitor.io/cve/CVE-2025-40541 #cybersecurity #infosec #CVE

    Post summary

    The post announces a critical IDOR vulnerability in SolarWinds Serv‑U that allows privileged code execution, but it does not provide PoC, exploit, or patch details.

    0000037
    8 followersView on X
  • protect_cyber_sec@AmirHossein_sec
    Patch

    برای یکی از نرم افزار شرکت SolarWinds یعنی Serv-U file transfer آسیب پذیری با کد شناسایی CVE-2025-40541 و از نوع RCE منتشر شده است که به هکرها امکان اجرای کد با دسترسی ROOT را می دهد. نمره این آسیب پذیری 9.1 می باشد. برای پیشگیری و مقابله ، به روز رسانی لازم را اعمال نمایید. https://t.co/xTK7It7tBt

    Post summary

    SolarWinds Serv‑U file transfer has a critical RCE vulnerability (CVE‑2025‑40541) with a CVSS score of 9.1; users are advised to apply the available update to mitigate the risk.

    0000054
    206 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Serv-U 15.5.4 Patches 4 Critical Flaws Enabling Root-Level Compromise SolarWinds released Serv-U v15.5.4 to fix four critical vulnerabilities (CVE-2025-40538 to CVE-2025-40541, CVSS 9.1) that can let attackers with high privileges create unauthorized system admins and execute native code as root via access-control, type confusion, and IDOR issues. Organizations running internet-facing Serv-U should patch immediately to reduce full-compromise risk (ransomware, data theft, persistent backdoors). 🎯 Target: Global/Enterprise File Transfer Infrastructure #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cybersecuritynews.com/solarwinds-serv-u-vulnerabilities-2/

    Post summary

    SolarWinds released Serv‑U v15.5.4 to patch four critical CVEs (CVE‑2025‑40538 to 40541) that enable root‑level compromise; organizations running internet‑facing Serv‑U should apply the patch immediately to mitigate ransomware, data theft, and backdoor risks.

    0000032
    214 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Serv-U Patches 4 Critical Flaws That Enable Root-Level Code Execution SolarWinds fixed four critical Serv-U vulnerabilities (CVE-2025-40538 to CVE-2025-40541) that could let an attacker with already-compromised admin/group-admin access create a system admin user and achieve privileged/native code execution up to root, with remote/low-complexity exploitation possible. Organizations should upgrade to Serv-U v15.5.4 ASAP; no confirmed in-the-wild exploitation was reported at publication. 🎯 Target: Global/Enterprise File Transfer Infrastructure #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/

    Post summary

    SolarWinds issued patches for four critical Serv‑U vulnerabilities that enable privileged code execution; organizations are urged to upgrade to v15.5.4, with no evidence of in‑the‑wild exploitation reported.

    0000029
    214 followersView on X
  • Shah Sheikh@shah_sheikh
    Patch

    SolarWinds Serv-U hit by four critical RCE-level vulnerabilities: SolarWinds has fixed four critical vulnerabilities in its popular Serv-U file transfer solution, which is used by businesses and organizations of all sizes. If exploited, the flaws may… https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/?utm_source=dlvr.it&utm_medium=twitter https://t.co/vaEGKYJGlu

    Post summary

    SolarWinds Serv-U has released patches for four critical RCE vulnerabilities, addressing the flaws reported in the linked article.

    0000047
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsserv-u---

Explore more