By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution
Computing

SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution

News Room
Last updated: 2026/02/25 at 3:23 AM
News Room Published 25 February 2026
Share
SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution
SHARE

Ravie LakshmananFeb 25, 2026Vulnerability / Windows Security

SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if successfully exploited, could result in remote code execution.

The vulnerabilities, all rated 9.1 on the CVSS scoring system, are listed below –

  • CVE-2025-40538 – A broken access control vulnerability that allows an attacker to create a system admin user and execute arbitrary code as root via domain admin or group admin privileges.
  • CVE-2025-40539 – A type confusion vulnerability that allows an attacker to execute arbitrary native code as root.
  • CVE-2025-40540 – A type confusion vulnerability that allows an attacker to execute arbitrary native code as root.
  • CVE-2025-40541 – An insecure direct object reference (IDOR) vulnerability that allows an attacker to execute native code as root.

SolarWinds noted that the vulnerabilities require administrative privileges for successful exploitation. It also said that they carry a medium security risk on Windows deployments as the services “frequently run under less-privileged service accounts by default.”

The four shortcomings affect SolarWinds Serv-U version 15.5. They have been addressed in SolarWinds Serv-U version 15.5.4.

While SolarWinds makes no mention of the security flaws being exploited in the wild, prior vulnerabilities in the software (CVE-2021-35211, CVE-2021-35247, and CVE-2024-28995) have been exploited by malicious actors, including by a China-based hacking group tracked as Storm-0322 (formerly DEV-0322).

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Best portable power station deal: Save 0 on Anker Solix C1000 Best portable power station deal: Save $370 on Anker Solix C1000
Next Article These Best Crypto to Buy in 2026 Could Explode: BlockDAG, Bittensor, Render, and Pippin! These Best Crypto to Buy in 2026 Could Explode: BlockDAG, Bittensor, Render, and Pippin!
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

New System Combines SLAM and Language Models for Online 3D Scene Mapping | HackerNoon
New System Combines SLAM and Language Models for Online 3D Scene Mapping | HackerNoon
Computing
The Best Subscription and Membership Services for Content Creators We’ve Tested
The Best Subscription and Membership Services for Content Creators We’ve Tested
News
Why Xbox’s corporate shake-up matters for everyone who plays games
Why Xbox’s corporate shake-up matters for everyone who plays games
News
GTK 4.22 In Good Shape With Better SVG Support
GTK 4.22 In Good Shape With Better SVG Support
Computing

You Might also Like

New System Combines SLAM and Language Models for Online 3D Scene Mapping | HackerNoon
Computing

New System Combines SLAM and Language Models for Online 3D Scene Mapping | HackerNoon

9 Min Read
GTK 4.22 In Good Shape With Better SVG Support
Computing

GTK 4.22 In Good Shape With Better SVG Support

2 Min Read
4G Capital says 92% of SME borrowers pay on time
Computing

4G Capital says 92% of SME borrowers pay on time

6 Min Read
Why AI Agent Reliability Depends More on the Harness Than the Model | HackerNoon
Computing

Why AI Agent Reliability Depends More on the Harness Than the Model | HackerNoon

30 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?