Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Best Software-Defined Perimeter (SDP) Solutions of 2024
August 17, 2026
Threema Messaging Service Suffers Massive DDoS Attack
August 17, 2026
HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Itself
August 17, 2026
Home/Vulnerabilities/SolarWinds Serv-U Critical RCE Bug CVE-2024-28925 Lets Attackers Gain Root Access
Vulnerabilities

SolarWinds Serv-U Critical RCE Bug CVE-2024-28925 Lets Attackers Gain Root Access

Key Takeaways SolarWinds has released Serv-U version 15.5.4 to patch four critical vulnerabilities. These flaws, rated 9.1 CVSS each, could allow attackers to achieve root-level remote code...

Sarah simpson
Sarah simpson
March 18, 2026 3 Min Read
51 0

Key Takeaways

  • SolarWinds has released Serv-U version 15.5.4 to patch four critical vulnerabilities.
  • These flaws, rated 9.1 CVSS each, could allow attackers to achieve root-level remote code execution.
  • Affected systems include unpatched versions of the Serv-U file server software.
  • A fix is available in Serv-U version 15.5.4, and immediate updates are strongly recommended.

A critical security update is urgently required for SolarWinds Serv-U file server software, as multiple severe vulnerabilities have been identified that could lead to complete system compromise if left unaddressed. The latest release, Serv-U version 15.5.4, specifically targets and remediates four high-severity security flaws, each carrying a CVSS score of 9.1.

Table Of Content

  • Key Takeaways
  • Serv-U Vulnerabilities Allow Root Access
  • Product Enhancements and Update Recommendations
  • What You Should Do

These vulnerabilities are particularly dangerous due to their potential for remote code execution (RCE), which would grant attackers the highest level of administrative control over affected infrastructure. Cybersecurity teams and system administrators are advised to review the official release notes and apply the necessary updates without delay to mitigate the risk of exploitation.

Serv-U Vulnerabilities Allow Root Access

The recently disclosed security issues fundamentally impact the core operations of the Serv-U application, allowing for the execution of arbitrary native code with root privileges. Among the most critical is a broken access control vulnerability, identified as CVE-2025-40538. This flaw enables attackers who possess domain or group administrator credentials to create a new system administrator user account. Once this unauthorized account is established, the adversary can execute malicious commands with full root privileges.

The software also suffers from two distinct type confusion vulnerabilities, CVE-2025-40539 and CVE-2025-40540. These memory corruption flaws in the Serv-U web interface offer a direct pathway for an attacker to run unauthorized native code as root. Furthermore, the update addresses an Insecure Direct Object Reference (IDOR) vulnerability, CVE-2025-40541, found in the Serv-U API and object handling. This specific flaw allows attackers to bypass authorization mechanisms by directly accessing internal objects, leading to remote code execution with root privileges.

The comprehensive control offered by these vulnerabilities means threat actors could leverage them for various malicious activities, including deploying ransomware, exfiltrating sensitive enterprise data, or establishing persistent backdoors within corporate networks. SolarWinds has publicly acknowledged and credited security researchers for their responsible disclosure of these issues and for collaborating with their engineering teams to develop effective patches.

Product Enhancements and Update Recommendations

Beyond the critical security patches, Serv-U version 15.5.4 introduces several functional improvements and expanded platform support. The application now officially supports Ubuntu 24.04 LTS, enhancing its deployment flexibility within enterprise environments. SolarWinds has also restored the download history feature in File Share, bringing it in line with capabilities found in the legacy web client. Additionally, the file share interface now displays a precise time alongside the last modified date.

To further bolster the application’s resilience against modern web threats, SolarWinds has implemented strict content security policy (CSP) configurations. The legacy login page, for instance, now uses specific directives designed to prevent the application from being maliciously embedded in other websites, thereby neutralizing potential clickjacking attacks. Administrators utilizing older versions of Serv-U should consult the end-of-life schedule, as earlier iterations, such as 15.5.1, reached the end of engineering support by February 18, 2026. Organizations are urged to download the latest installation files from the customer portal to ensure their infrastructure remains secure against these critical remote code execution threats.

What You Should Do

  • Immediately update all Serv-U installations to version 15.5.4.
  • Review the official SolarWinds Serv-U 15.5.4 release notes for full details on the patched vulnerabilities and new features.
  • Verify that your Serv-U instances are running supported versions to ensure continued access to security updates.
  • Implement strict network segmentation and access controls to limit potential lateral movement in case of a breach.
  • Regularly back up critical data and test recovery procedures.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVECybersecurityExploitPatchransomwareSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

CISA Warns of Active Exploitation in Soliton FileZen CVE-2023-40074

Next Post

Critical ScreenConnect Vulnerability Lets Attackers Extract Keys, Hijack Sessions

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Z.ai Launches GLM-5.3, Boosting Cybersecurity and Coding Capabilities
August 17, 2026
Critical GeoServer SQLi Vulnerability Allows Remote Code Execution
August 17, 2026
MessiahGPT AI Model Automates Ransomware and Phishing Attacks
August 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us