CVE-2025-40548: SolarWinds Serv-U
Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.
A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
Affected products
- SolarWinds Serv-U: before 15.5.3 (fixed in 15.5.3)
Published 2025-11-18. Last modified 2026-10-07.