Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SolarWinds Fixes Major Flaws in Serv-U Software

SolarWinds Fixes Major Flaws in Serv-U Software

Posted on February 25, 2026 By CWS

SolarWinds has announced the release of updates to rectify four significant security vulnerabilities in its Serv-U file transfer software. These flaws, if exploited, could lead to remote code execution, posing a substantial threat to affected systems. The vulnerabilities in question have been assigned a CVSS score of 9.1, indicating their severity and potential impact on system security.

Details of the Vulnerabilities

The identified vulnerabilities include a broken access control issue, labeled CVE-2025-40538, which permits attackers to create a system admin user and execute arbitrary code with root privileges through domain or group admin access. Additionally, two type confusion vulnerabilities, CVE-2025-40539 and CVE-2025-40540, have been identified, both capable of allowing execution of native code as root. Lastly, an insecure direct object reference vulnerability, CVE-2025-40541, also enables the execution of native code with root privileges.

Impact and Mitigation

SolarWinds has clarified that exploiting these vulnerabilities necessitates administrative privileges, and they present a medium security risk for Windows deployments. This is due to the fact that the services typically operate under less-privileged accounts by default. The vulnerabilities affect Serv-U version 15.5 and have been resolved with the release of version 15.5.4.

Previous Exploitations and Security Measures

While there is no current evidence suggesting these specific flaws have been actively exploited, historical vulnerabilities within the software have been targeted by malicious entities. Notably, past issues like CVE-2021-35211, CVE-2021-35247, and CVE-2024-28995 were exploited by hackers, including a group associated with China, known as Storm-0322. This underscores the importance of promptly applying the latest updates to safeguard systems against potential threats.

In conclusion, the resolution of these vulnerabilities is crucial for maintaining system integrity and protecting against unauthorized code execution. Users of SolarWinds Serv-U are strongly encouraged to upgrade to the latest version to ensure their systems remain secure against these critical threats.

The Hacker News Tags:CVSS, Cybersecurity, Patch, remote code execution, Security, Serv-U, software update, SolarWinds, Vulnerabilities, Windows security

Post navigation

Previous Post: Hackers Exploit Next.js Repositories Targeting Developers
Next Post: AI Vulnerability Tool Disrupts Cybersecurity Market

Related Posts

Konni Hackers Turn Google’s Find Hub into a Remote Data-Wiping Weapon Konni Hackers Turn Google’s Find Hub into a Remote Data-Wiping Weapon The Hacker News
Addressing the Hidden Costs of Credential Incidents Addressing the Hidden Costs of Credential Incidents The Hacker News
CISA Adds Two N-able N-central Flaws to Known Exploited Vulnerabilities Catalog CISA Adds Two N-able N-central Flaws to Known Exploited Vulnerabilities Catalog The Hacker News
Meta Disrupts Influence Ops Targeting Romania, Azerbaijan, and Taiwan with Fake Personas Meta Disrupts Influence Ops Targeting Romania, Azerbaijan, and Taiwan with Fake Personas The Hacker News
Google Disrupts IPIDEA — One of the World’s Largest Residential Proxy Networks Google Disrupts IPIDEA — One of the World’s Largest Residential Proxy Networks The Hacker News
Top 10 Best Practices for Effective Data Protection Top 10 Best Practices for Effective Data Protection The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GlassWorm Botnet Dismantled by Cybersecurity Experts
  • Enhancing SOC Risk Visibility for CISOs
  • AI’s Growing Threat: UK’s Cyber Chief Warns of Russia
  • Malicious npm Package Targets Claude AI User Data
  • Critical ‘BadHost’ Flaw Threatens AI Server Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GlassWorm Botnet Dismantled by Cybersecurity Experts
  • Enhancing SOC Risk Visibility for CISOs
  • AI’s Growing Threat: UK’s Cyber Chief Warns of Russia
  • Malicious npm Package Targets Claude AI User Data
  • Critical ‘BadHost’ Flaw Threatens AI Server Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark