CVE-2025-40539: 
Serv-U Managed File Transfer Server vulnerability analysis and mitigation

Overview

CVE-2025-40539 is a type confusion (CWE-704) remote code execution vulnerability in SolarWinds Serv-U that allows an authenticated attacker with administrative privileges to execute arbitrary native code as a privileged account. It affects all Serv-U versions prior to 15.5.4 and was publicly disclosed on February 24, 2026. SolarWinds rates this vulnerability with a CVSS v3.1 score of 9.1 (Critical) using a scope-changed vector, though the NVD scores it at 7.2 (High) reflecting the high privilege requirement; on Windows deployments, SolarWinds notes the practical risk is medium due to services typically running under less-privileged accounts (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).

Technical details

The vulnerability is classified as CWE-704 (Incorrect Type Conversion or Cast), where Serv-U incorrectly handles type conversions internally, enabling an attacker to manipulate program control flow and execute arbitrary native code. Exploitation requires network access and administrative credentials, but no user interaction is needed. The vulnerability is one of four critical RCE flaws patched simultaneously in Serv-U 15.5.4, alongside CVE-2025-40538 (broken access control), CVE-2025-40540 (type confusion), and CVE-2025-40541 (IDOR), all rated 9.1 Critical (SolarWinds Advisory, Serv-U 15.5.4 Release Notes). No public technical write-up or proof-of-concept code has been identified at this time.

Impact

Successful exploitation allows an attacker with administrative access to execute arbitrary native code as a privileged (root/SYSTEM) account on the Serv-U host, resulting in complete compromise of confidentiality, integrity, and availability. On Linux deployments, this translates to full root-level code execution, enabling data exfiltration, persistent backdoor installation, and lateral movement within the network. On Windows, the practical impact may be reduced if Serv-U runs under a least-privileged service account, but systems configured with elevated privileges remain fully at risk (SolarWinds Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.043%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires administrative credentials, which significantly raises the bar for opportunistic attackers, though insider threats or attackers who have already compromised admin accounts remain a concern.

Mitigation and workarounds

SolarWinds has released Serv-U version 15.5.4 (released February 24, 2026) as the official fix for CVE-2025-40539. Organizations should upgrade immediately from any version prior to 15.5.4. As interim hardening measures, restrict administrative access to Serv-U to only authorized personnel, enforce multi-factor authentication for admin accounts, and on Windows ensure Serv-U runs under a least-privileged service account rather than with full system privileges. Monitor for suspicious administrative activity or unexpected code execution on Serv-U systems (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).

Community reactions

The disclosure attracted broad coverage from security media, with outlets including The Hacker News, The Register, Security Affairs, Help Net Security, and CSO Online reporting on the batch of four critical Serv-U RCE flaws patched simultaneously (The Hacker News, The Register, Security Affairs). Security researchers and community members on Mastodon and Bluesky noted the severity of root-level code execution potential. SOCRadar and Orca Security published technical digests summarizing the vulnerabilities and urging immediate patching (SOCRadar, Orca Security). The Belgium CCB and WaterISAC also issued advisories recommending urgent remediation.

Additional resources


Source: This report was generated using AI

Related Serv-U Managed File Transfer Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28321CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28317CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28316CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28314CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28315MEDIUM6.2
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management