SolarWinds Security Updates – 24 February 2026

SolarWinds has released security updates to address several vulnerabilities affecting SolarWinds Serv-U 15.5.

The addressed vulnerabilities could allow the attacker to perform an Insecure Direct Object Reference (IDOR) attack, conduct a broken access control attack, or execute arbitrary code and gain access to the affected systems.

Sample of the addressed vulnerabilities:

SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability (CVE- 2025-40539):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2025-40538
  • CVE-2025-40539
  • CVE-2025-40540
  • CVE-2025-40541
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Updates

References