
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40539 is a type confusion (CWE-704) remote code execution vulnerability in SolarWinds Serv-U that allows an authenticated attacker with administrative privileges to execute arbitrary native code as a privileged account. It affects all Serv-U versions prior to 15.5.4 and was publicly disclosed on February 24, 2026. SolarWinds rates this vulnerability with a CVSS v3.1 score of 9.1 (Critical) using a scope-changed vector, though the NVD scores it at 7.2 (High) reflecting the high privilege requirement; on Windows deployments, SolarWinds notes the practical risk is medium due to services typically running under less-privileged accounts (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).
The vulnerability is classified as CWE-704 (Incorrect Type Conversion or Cast), where Serv-U incorrectly handles type conversions internally, enabling an attacker to manipulate program control flow and execute arbitrary native code. Exploitation requires network access and administrative credentials, but no user interaction is needed. The vulnerability is one of four critical RCE flaws patched simultaneously in Serv-U 15.5.4, alongside CVE-2025-40538 (broken access control), CVE-2025-40540 (type confusion), and CVE-2025-40541 (IDOR), all rated 9.1 Critical (SolarWinds Advisory, Serv-U 15.5.4 Release Notes). No public technical write-up or proof-of-concept code has been identified at this time.
Successful exploitation allows an attacker with administrative access to execute arbitrary native code as a privileged (root/SYSTEM) account on the Serv-U host, resulting in complete compromise of confidentiality, integrity, and availability. On Linux deployments, this translates to full root-level code execution, enabling data exfiltration, persistent backdoor installation, and lateral movement within the network. On Windows, the practical impact may be reduced if Serv-U runs under a least-privileged service account, but systems configured with elevated privileges remain fully at risk (SolarWinds Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.043%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires administrative credentials, which significantly raises the bar for opportunistic attackers, though insider threats or attackers who have already compromised admin accounts remain a concern.
SolarWinds has released Serv-U version 15.5.4 (released February 24, 2026) as the official fix for CVE-2025-40539. Organizations should upgrade immediately from any version prior to 15.5.4. As interim hardening measures, restrict administrative access to Serv-U to only authorized personnel, enforce multi-factor authentication for admin accounts, and on Windows ensure Serv-U runs under a least-privileged service account rather than with full system privileges. Monitor for suspicious administrative activity or unexpected code execution on Serv-U systems (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).
The disclosure attracted broad coverage from security media, with outlets including The Hacker News, The Register, Security Affairs, Help Net Security, and CSO Online reporting on the batch of four critical Serv-U RCE flaws patched simultaneously (The Hacker News, The Register, Security Affairs). Security researchers and community members on Mastodon and Bluesky noted the severity of root-level code execution potential. SOCRadar and Orca Security published technical digests summarizing the vulnerabilities and urging immediate patching (SOCRadar, Orca Security). The Belgium CCB and WaterISAC also issued advisories recommending urgent remediation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."