Back

CRITICAL

SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability

Published Feb 24, 2026

Description

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account.

This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

Affected products

Remediation

Vendor solution

SolarWinds recommends that customers upgrade to SolarWinds Serv-U 15.5.4 as soon as it becomes available.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SolarWinds
Published Feb 24, 2026
Updated Feb 26, 2026
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Feb 25, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a