Skip to content
English

Products › Brands

Brand

SolarWinds: actively exploited vulnerabilities

11 vulnerabilities in SolarWinds products (Web Help Desk, Serv-U, Orion Platform…) are in CISA’s catalog of exploited vulnerabilities. Last added: June 5, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one SolarWinds category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • Web Help Desk 5 vulnerabilities · Monitoring and ITSM
  • Serv-U 4 vulnerabilities · File transfer (MFT)
  • Orion Platform 1 vulnerability · Monitoring and ITSM
  • Virtualization Manager 1 vulnerability · Monitoring and ITSM

Name used by CISA: SolarWinds. Product families: indicative classification by this site.

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this SolarWinds list.

  1. Rank 1SolarWinds Web Help Desk

    CVE-2025-26399

    Ransomware

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 9, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 2SolarWinds Web Help Desk

    CVE-2025-40536

    SolarWinds Web Help Desk Security Control Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 12, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 3SolarWinds Web Help Desk

    CVE-2025-40551

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 3, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Rank 4SolarWinds Serv-U

    CVE-2026-28318

    SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 5, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  5. Rank 5SolarWinds Serv-U

    CVE-2021-35211

    Ransomware

    SolarWinds Serv-U Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  6. Rank 6SolarWinds Web Help Desk

    CVE-2024-28986

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 7SolarWinds Orion Platform

    CVE-2020-10148

    SolarWinds Orion Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  8. Rank 8SolarWinds Web Help Desk

    CVE-2024-28987

    SolarWinds Web Help Desk Hardcoded Credential Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  9. Rank 9SolarWinds Virtualization Manager

    CVE-2016-3643

    CVE from 2016, added in 2021

    SolarWinds Virtualization Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  10. Rank 10SolarWinds Serv-U

    CVE-2024-28995

    SolarWinds Serv-U Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 17, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
Show 1 more vulnerability
  1. Rank 11SolarWinds Serv-U

    CVE-2021-35247

    SolarWinds Serv-U Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 21, 2022
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)

Follow and verify

Get new SolarWinds vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.