惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
M
MIT News - Artificial intelligence
G
Google Developers Blog
P
Proofpoint News Feed
Recent Announcements
Recent Announcements
MyScale Blog
MyScale Blog
D
DataBreaches.Net
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
爱范儿
爱范儿
罗磊的独立博客
腾讯CDC
Hugging Face - Blog
Hugging Face - Blog
博客园 - 叶小钗
Vercel News
Vercel News
酷 壳 – CoolShell
酷 壳 – CoolShell
B
Blog
C
Check Point Blog
美团技术团队
宝玉的分享
宝玉的分享
Microsoft Security Blog
Microsoft Security Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day Critical Microsoft bug from 2024 under exploitation
Patch these 4 critical, make-me-root SolarWinds bugs ASAP
Jessica Lyons Jessica Lyons · 2026-02-25 · via The Register - Security: Patches

Patches

SolarWinds + file transfer software = what attackers' dreams are made of

If you run SolarWinds’ Serv-U, you should patch promptly. Four critical vulnerabilities in the file transfer software can allow attackers to execute code as root.

The four flaws, all of which earned a 9.1 CVSS rating, include a broken access control vulnerability (CVE-2025-40538), two type confusion bugs (CVE-2025-40540 and CVE-2025-40539), and an Insecure Direct Object Reference (IDOR) issue (CVE-2025-40541), all of which can lead to remote code execution (RCE).

The most serious of the four, CVE-2025-40538, "gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges," according to the vendor's security advisory.

Updating to the latest version, Serv-U 15.5.4, patches all four security holes.

In a statement to The Register, SolarWinds said, "We are aware of the reported issues and successfully addressed them as part of the Serv-U 15.5.4 release. We have not observed exploitation. We remain committed to monitoring the situation, working closely with customers and partners to ensure issues are resolved quickly. SolarWinds continues to prioritize the swift resolution of CVEs to ensure the security and integrity of our software."

The good news is that all four require administrative privileges to abuse, and none of the new CVEs have appeared on the US Cybersecurity and Infrastructure Security Agency's (CISA's) catalog of Known Exploited Vulnerabilities - yet. 

However, SolarWinds' products in general are a long-time favorite target for attackers, and CISA has added three earlier Serv-U bugs to its KEV, including one known to be used in ransomware infections

Plus, criminals frequently abuse file sharing products (such as MOVEit, and GoAnywhere) because enterprises use them to store and transfer large volumes of highly sensitive files, such as financial records, and intellectual property, and this makes them a high-value target.

We highly recommend updating the software as soon as possible.

Earlier this month, CISA warned that unknown attackers were exploiting a critical SolarWinds Web Help Desk bug, CVE-2025-40551, less than a week after the vendor disclosed and fixed the 9.8-rated flaw. 

A couple of days after America's lead cyber-defense agency sounded the alarm, Microsoft said it spotted a multi-stage intrusion where attackers exploited internet-exposed SolarWinds WHD instances to gain access to the victim organization, and then moved laterally to other high-value assets. ®