CVE-2025-40539 – SolarWinds Serv-U Security Update
“These Serv-U issues can let attackers run code remotely and take over the server.”
SolarWinds released fixes for four critical remote code execution vulnerabilities in Serv-U. Each issue is scored CVSS 9.1 (Critical): CVE-2025-40538, CVE-2025-40539, CVE-2025-40540, and CVE-2025-40541. Collectively, these weaknesses can allow remote code execution against affected Serv-U deployments, which can translate into complete compromise of the Serv-U host and rapid expansion into the wider environment.
These vulnerabilities are especially dangerous because Serv-U often sits on the edge of the network and handles sensitive file movement. Successful exploitation can enable attackers to run commands, alter services, steal data in transit or at rest, and use the server as a staging point for broader intrusion.
Key Details
- Affected Product
- Solarwinds Serv-u
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-704