Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SolarWinds Patches Three Critical Serv-U Vulnerabilities

SolarWinds Patches Three Critical Serv-U Vulnerabilities

Posted on November 20, 2025November 20, 2025 By CWS

SolarWinds this week introduced patches for 3 vital vulnerabilities present in its Serv-U enterprise file switch resolution. 

One of many flaws, tracked as CVE-2025-40549, has been described as a path restriction bypass situation that may be exploited by a risk actor with administrator privileges to execute arbitrary code on a listing. 

The seller identified that on Home windows programs the vulnerability has a ‘medium severity’ score as a result of “variations in how paths and residential directories are dealt with”.

The second vulnerability is CVE-2025-40548, a damaged entry management situation that may be exploited by an attacker with admin privileges to execute arbitrary code.

The third flaw, CVE-2025-40547, is a logic error that may be exploited for code execution by an attacker with admin permissions.

For each CVE-2025-40547 and CVE-2025-40548, SolarWinds famous that their severity score is ‘medium’ on Home windows as a result of companies usually run by default underneath less-privileged accounts.

The three safety holes have an effect on SolarWinds Serv-U 15.5.2.2.102 and so they have been patched with the discharge of model 15.5.3.

SolarWinds this week additionally introduced patches for medium-severity open redirection and XSS vulnerabilities in Observability Self-Hosted.Commercial. Scroll to proceed studying.

It’s not unusual for risk actors to use SolarWinds product vulnerabilities of their assaults, together with Serv-U flaws.

The Identified Exploited Vulnerabilities (KEV) catalog maintained by the cybersecurity company CISA at the moment consists of seven SolarWinds flaws, together with ones impacting Internet Assist Desk, Orion, Virtualization Supervisor, and Serv-U. 

Associated: SolarWinds Makes Third Try at Patching Exploited Vulnerability

Associated: CISA Flags Crucial SolarWinds Internet Assist Desk Bug for In-the-Wild Exploitation

Associated: SolarWinds Patches Excessive-Severity Vulnerability Reported by NATO Pentester

Associated: SolarWinds Patches Crucial Vulnerability in Entry Rights Supervisor

Security Week News Tags:Critical, Patches, ServU, SolarWinds, Vulnerabilities

Post navigation

Previous Post: China-Nexus APT Group Leverages DLL Sideloading Technique to Attack Government and Media Sectors
Next Post: Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt

Related Posts

CISA KEV Catalog Expanded 20% in 2025, Topping 1,480 Entries CISA KEV Catalog Expanded 20% in 2025, Topping 1,480 Entries Security Week News
OpenSSL Patch Resolves Critical ‘HollowByte’ Vulnerability OpenSSL Patch Resolves Critical ‘HollowByte’ Vulnerability Security Week News
Perspective: Why Politics in the Workplace is a Cybersecurity Risk Perspective: Why Politics in the Workplace is a Cybersecurity Risk Security Week News
New 0 Cellik RAT Grants Android Control, Trojanizes Google Play Apps New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps Security Week News
Hackers Abuse ConnectWise to Hide Malware Hackers Abuse ConnectWise to Hide Malware Security Week News
NIST Publishes Guide for Protecting ICS Against USB-Borne Threats NIST Publishes Guide for Protecting ICS Against USB-Borne Threats Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark