CVE-2025-40538: 
Serv-U Managed File Transfer Server vulnerability analysis and mitigation

Overview

CVE-2025-40538 is a broken access control vulnerability in SolarWinds Serv-U that allows a malicious actor with domain admin or group admin privileges to create a system administrator account and execute arbitrary code as a privileged account. It affects all Serv-U versions prior to 15.5.4 and was disclosed on February 24, 2026. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) per the SolarWinds advisory, though NVD scores it at 7.2 (High) — the discrepancy reflects differing scope assessments, with SolarWinds noting a Changed scope on Linux deployments and a Medium risk on Windows where services run under less-privileged accounts (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).

Technical details

The vulnerability is classified as CWE-269 (Improper Privilege Management) and stems from broken access control logic within Serv-U's administrative interface. A domain admin or group admin — roles that are subordinate to system admin — can exploit insufficient authorization checks to elevate their privileges by creating a new system administrator account, then leverage that account to execute arbitrary code as root (on Linux) or as the service account (on Windows). The attack vector is network-based, requires no user interaction, and has low attack complexity, but does require the attacker to already possess domain or group admin credentials within the Serv-U environment (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).

Impact

Successful exploitation allows an attacker to create unauthorized system administrator accounts and execute arbitrary code with the highest available privileges — root on Linux deployments, or the service account on Windows. This results in high impact to confidentiality, integrity, and availability of the Serv-U system, potentially enabling full server takeover, data exfiltration of all managed file transfers, and use of the compromised server as a pivot point for lateral movement within the network. On Windows, the risk is somewhat reduced because Serv-U services frequently run under less-privileged service accounts by default (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.026%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to already hold domain admin or group admin credentials within the Serv-U environment, which limits the attack surface compared to unauthenticated vulnerabilities. No threat actor attribution has been reported (SolarWinds Advisory).

Exploitation steps

  1. Credential Acquisition: Obtain domain admin or group admin credentials for the target Serv-U instance through phishing, credential stuffing, or compromise of a lower-privileged Serv-U account.
  2. Authentication: Log in to the Serv-U administrative interface using the acquired domain admin or group admin credentials over the network.
  3. Privilege Escalation via Account Creation: Exploit the broken access control flaw by sending crafted administrative requests to create a new system administrator account — a privilege that should be restricted to existing system admins but is improperly permitted for domain/group admins.
  4. Re-authenticate as System Admin: Log in with the newly created system administrator account to gain full administrative control over the Serv-U instance.
  5. Arbitrary Code Execution: Leverage system admin privileges to execute arbitrary code as root (Linux) or as the service account (Windows), enabling deployment of backdoors, data exfiltration, or further lateral movement (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).

Indicators of compromise

  • Logs: Unexpected creation of new system administrator accounts in Serv-U audit logs, particularly by accounts with domain admin or group admin roles; administrative actions performed by accounts not previously holding system admin privileges.
  • Logs: Serv-U activity logs showing privilege escalation events or unusual administrative API calls originating from domain/group admin sessions.
  • Network: Administrative interface access from unusual source IP addresses or at unusual times, especially if followed immediately by account creation events.
  • File System (Linux): Unexpected processes spawned as root by the Serv-U service; new files or scripts written to sensitive directories (e.g., /etc, /opt) by the Serv-U process.
  • Process: Unusual child processes launched by the Serv-U daemon, such as shell interpreters (/bin/bash, /bin/sh) or network utilities (curl, wget, nc) on Linux hosts.

Mitigation and workarounds

SolarWinds has released Serv-U 15.5.4 (released February 24, 2026) to address this vulnerability; all organizations running Serv-U versions prior to 15.5.4 should upgrade immediately (Serv-U 15.5.4 Release Notes, SolarWinds Advisory). No vendor-provided workaround is available for those unable to patch immediately. As interim mitigations, organizations should restrict domain admin and group admin privileges to only trusted personnel with a legitimate need, implement strong monitoring and alerting for new system administrator account creation, and review existing Serv-U admin accounts for unauthorized additions.

Community reactions

The disclosure generated significant coverage across security media, with outlets including BleepingComputer, The Register, SecurityAffairs, HelpNet Security, and CSO Online reporting on the four critical Serv-U flaws patched simultaneously, framing them as enabling "root access" to servers (BleepingComputer, The Register). Government CERTs including Canada's CCCS, Belgium's CCB, and Thailand's ThaiCERT issued advisories urging prompt patching. Community discussion on Reddit and Mastodon highlighted the pattern of high-severity disclosures from SolarWinds Serv-U, with CSO Online noting this extends "SolarWinds' run of high-severity disclosures" (CSO Online). Orca Security published a technical blog post analyzing the RCE vulnerabilities in the batch (Orca Security).

Additional resources


Source: This report was generated using AI

Related Serv-U Managed File Transfer Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28321CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28317CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28316CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28314CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28315MEDIUM6.2
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management