SolarWinds Vulnerabilities
SolarWinds makes IT management software, and the products in KEV are the Orion Platform, Serv-U managed file transfer, Web Help Desk and Virtualization Manager. The database tracks 11 SolarWinds CVE records. CISA lists 11 of them as exploited in the wild, most recently on 2026-06-05. The most affected products are Web Help Desk, Serv-U, Orion.
Recently Exploited SolarWinds CVEs
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability
SolarWinds Web Help Desk Security Control Bypass Vulnerability
SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability
Affected Products
4 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Web Help Desk | 5 | 5 | 2026-03-09 |
| Serv-U | 4 | 4 | 2026-06-05 |
| Orion | 1 | 1 | 2021-11-03 |
| Virtualization Manager | 1 | 1 | 2021-11-03 |
All SolarWinds CVEs
11 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-28318 | SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability | SolarWinds | 7.5 | 1.9% | KEV | 2026-06-04 |
| CVE-2025-26399 | SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability | SolarWinds | 9.8 | 89.5% | KEV | 2025-09-23 |
| CVE-2025-40536 | SolarWinds Web Help Desk Security Control Bypass Vulnerability | SolarWinds | 8.1 | 73.6% | KEV | 2026-01-28 |
| CVE-2025-40551 | SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability | SolarWinds | 9.8 | 84.2% | KEV | 2026-01-28 |
| CVE-2024-28987 | SolarWinds Web Help Desk Hardcoded Credential Vulnerability | SolarWinds | 9.1 | 93.3% | KEV | 2024-08-21 |
| CVE-2024-28986 | SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability | SolarWinds | 9.8 | 84.6% | KEV | 2024-08-13 |
| CVE-2024-28995 | SolarWinds Serv-U L Directory Transversal Vulnerability | SolarWinds | 8.6 | 99.6% | KEV | 2024-06-06 |
| CVE-2021-35247 | Improper Input Validation Vulnerability in Serv-U | SolarWinds | 4.3 | 3.5% | KEV | 2022-01-07 |
| CVE-2020-10148 | SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands | SolarWinds | 9.8 | 92.0% | KEV | 2020-12-29 |
| CVE-2021-35211 | Serv-U Remote Memory Escape Vulnerability | SolarWinds | 9.0 | 91.2% | KEV | 2021-07-14 |
| CVE-2016-3643 | SolarWinds Virtualization Manager Privilege Escalation Vulnerability | - | 7.8 | 3.7% | KEV | 2016-06-17 |
Frequently Asked Questions
How many SolarWinds vulnerabilities are actively exploited?→
11 SolarWinds CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-06-05.
Which SolarWinds vulnerabilities are used in ransomware attacks?→
CISA marks 2 SolarWinds KEV entries as known to be used in ransomware campaigns, including CVE-2025-26399, CVE-2021-35211.
Which SolarWinds products have the most exploited vulnerabilities?→
- +Web Help Desk: 5 CVEs (5 in KEV)
- +Serv-U: 4 CVEs (4 in KEV)
- +Orion: 1 CVE (1 in KEV)
- +Virtualization Manager: 1 CVE (1 in KEV)
Where does SolarWinds publish security advisories?→
SolarWinds publishes security advisories at https://www.solarwinds.com/trust-center/security-advisories. Check the vendor advisory for fixed versions and workarounds before applying updates.
Sources
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by SolarWinds, MITRE, CISA, or FIRST.