SolarWinds
SolarWinds known exploited vulnerabilities
Every SolarWinds vulnerability in CISA's Known Exploited Vulnerabilities catalog, newest first. 2 of them are known to be used by ransomware.
11 CVEs
- CVE-2026-28318SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability · added June 5, 2026
- CVE-2025-26399 ransomwareSolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability · added March 9, 2026
- CVE-2025-40536SolarWinds Web Help Desk Security Control Bypass Vulnerability · added February 12, 2026
- CVE-2025-40551SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability · added February 3, 2026
- CVE-2024-28987SolarWinds Web Help Desk Hardcoded Credential Vulnerability · added October 15, 2024
- CVE-2024-28986SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability · added August 15, 2024
- CVE-2024-28995SolarWinds Serv-U Path Traversal Vulnerability · added July 17, 2024
- CVE-2021-35247SolarWinds Serv-U Improper Input Validation Vulnerability · added January 21, 2022
- CVE-2021-35211 ransomwareSolarWinds Serv-U Remote Code Execution Vulnerability · added November 3, 2021
- CVE-2020-10148SolarWinds Orion Authentication Bypass Vulnerability · added November 3, 2021
- CVE-2016-3643SolarWinds Virtualization Manager Privilege Escalation Vulnerability · added November 3, 2021
Source: CISA Known Exploited Vulnerabilities Catalog (public domain).