【Vulnerability Alert】 Four Critical Security Vulnerabilities Identified in SolarWinds Serv-U Software
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026030209035050 | Publication Time | 2026/03/02 09:40 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/03/02 09:40 |
| Impact Level | Low | ||
| [Subject] [Vulnerability Alert] Four Critical Security Vulnerabilities Identified in SolarWinds Serv-U Software |
|||
|
[Content] 【CVE-2025-40538, CVSS: 9.1】 This is an access control vulnerability that allows an attacker to create a system administrator account and execute arbitrary code with privileged account permissions through domain administrator or group administrator privileges. 【CVE-2025-40539, CVSS: 9.1】 This is a type confusion vulnerability that allows an attacker to execute arbitrary local code with privileged account permissions. 【CVE-2025-40540, CVSS: 9.1】 This is a type confusion vulnerability that allows an attacker to execute arbitrary local code with privileged account permissions. 【CVE-2025-40541, CVSS: 9.1】 This is an insecure direct object reference (IDOR) vulnerability that allows an attacker to execute arbitrary local code with privileged account permissions." |
|||
| [Affected Platform] SolarWinds Serv-U version 15.5 |
|||
| [Recommended Actions] Please update to the following version: SolarWinds Serv-U version 15.5.4 and later versions. |
|||
| [Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





