Multiple Vulnerabilities in SolarWinds Serv-U (CVE-2025-40549, CVE-2025-40548, CVE-2025-40547)

Published On: Nov 26, 2025 09:28

Advisory No: TZCERT-SA-25-0120

Source: SolarWinds

Software Affected: SolarWinds Serv-U

Overview

SolarWinds Serv-U is vulnerable to critical vulnerabilities. Exploitation of these vulnerabilities may allow an authenticated attacker to execute arbitrary code.

Description

SolarWinds Serv-U is affected by the vulnerabilities tracked as CVE-2025-40549, CVE-2025-40548, and CVE-2025-40547 with CVSS scores of 9.1 each. The product is vulnerable due to a Path Restriction Bypass, a missing validation process, and a logic error vulnerability. The vulnerabilities allow a malicious actor with access to admin privileges the ability to execute code.

Impact

Successful exploitation of these vulnerabilities may allow the attackers to take control of the affected system.

Solution

SolarWinds has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.

Subscribe To TZ - CERT Newsletter

A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.

Subscribe
Report Incident