<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/marques/solarwinds.xml</id>
  <title>Exploit Radar: exploited SolarWinds vulnerabilities</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities for SolarWinds products.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/marques/solarwinds.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/marques/solarwinds/"/>
  <updated>2026-06-05T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-28318/</id>
    <title>CVE-2026-28318 — SolarWinds Serv-U</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-28318/"/>
    <updated>2026-06-05T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SolarWinds; if none are available, stop using the product. For cloud services, follow the guidance from SolarWinds. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on June 5, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-26399/</id>
    <title>CVE-2025-26399 — SolarWinds Web Help Desk</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-26399/"/>
    <updated>2026-03-09T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SolarWinds; if none are available, stop using the product. For cloud services, follow the guidance from SolarWinds. CISA deadline: 3 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on March 9, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-40536/</id>
    <title>CVE-2025-40536 — SolarWinds Web Help Desk</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-40536/"/>
    <updated>2026-02-12T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SolarWinds; if none are available, stop using the product. For cloud services, follow the guidance from SolarWinds. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on February 12, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-40551/</id>
    <title>CVE-2025-40551 — SolarWinds Web Help Desk</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-40551/"/>
    <updated>2026-02-03T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SolarWinds; if none are available, stop using the product. For cloud services, follow the guidance from SolarWinds. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on February 3, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-28987/</id>
    <title>CVE-2024-28987 — SolarWinds Web Help Desk</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-28987/"/>
    <updated>2024-10-15T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SolarWinds; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on October 15, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-28986/</id>
    <title>CVE-2024-28986 — SolarWinds Web Help Desk</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-28986/"/>
    <updated>2024-08-15T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SolarWinds; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 15, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-28995/</id>
    <title>CVE-2024-28995 — SolarWinds Serv-U</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-28995/"/>
    <updated>2024-07-17T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from SolarWinds; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 17, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-35247/</id>
    <title>CVE-2021-35247 — SolarWinds Serv-U</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-35247/"/>
    <updated>2022-01-21T00:00:00Z</updated>
    <summary type="text">Apply the security update from SolarWinds. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on January 21, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-35211/</id>
    <title>CVE-2021-35211 — SolarWinds Serv-U</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-35211/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from SolarWinds. CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-10148/</id>
    <title>CVE-2020-10148 — SolarWinds Orion Platform</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-10148/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from SolarWinds. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2016-3643/</id>
    <title>CVE-2016-3643 — SolarWinds Virtualization Manager</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2016-3643/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from SolarWinds. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
