SolarWinds
First CVE: Jul 14, 2021Active for: 5 years
199
CVEs Published
More CVEs Published than 79% of tracked CNAs
33.2
Avg CVEs / Year
More Avg CVEs / Year than 78% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 62% of tracked CNAs
4.5%
In CISA KEV
Higher KEV Rate than 96% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by SolarWinds as a CNA, 89.9% affect products that SolarWinds develops as a vendor.
89.9%
10.1%
Self-reported: 179Third-party: 20
Of all the CVEs published that affect products developed by SolarWinds, 56.1% are self-published by SolarWinds as a CNA.
56.1%
43.9%
Self-published: 179Published by other CNAs: 140
Trends Over Time
The number and severity of CVEs published by SolarWinds over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2021
5 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by SolarWinds as a CNA, regardless of affected vendor or product.
199 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40551CRITICAL SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to r | Jan 28, 2026 | 9.8 | 98 | YES | YES |
CVE-2025-40536CRITICAL SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain | Jan 28, 2026 | 9.8 | 98 | YES | YES |
CVE-2024-28987CRITICAL The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify da | Aug 21, 2024 | 9.1 | 98 | YES | YES |
CVE-2024-28995HIGH SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. | Jun 6, 2024 | 7.5 | 98 | YES | YES |
CVE-2024-28986CRITICAL SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on th | Aug 13, 2024 | 9.8 | 97 | YES | YES |
CVE-2025-26399CRITICAL SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker | Sep 23, 2025 | 9.8 | 96 | YES | NO |
CVE-2021-35211CRITICAL Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may b | Jul 14, 2021 | 10.0 | 95 | YES | NO |
CVE-2024-0692HIGH The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, result | Mar 1, 2024 | 8.8 | 85 | NO | YES |
CVE-2026-28318HIGH SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provi | Jun 4, 2026 | 7.5 | 82 | YES | NO |
CVE-2025-40554CRITICAL SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Hel | Jan 28, 2026 | 9.8 | 79 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA199 CVEs
33%
45%
21%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (9.0%)
Network136 (68.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network45 (22.6%)
Attack Complexity
Low189 (95.0%)
High10 (5.0%)
Unknown0 (0.0%)
User Interaction
None169 (84.9%)
Unknown0 (0.0%)
Required30 (15.1%)
Privileges Required
Low72 (36.2%)
High60 (30.2%)
None67 (33.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (199 CVEs).
CISA KEV
9 CVEs
4.5% of CVEs· 96th percentile
Metasploit
5 CVEs
2.5% of CVEs· 93rd percentile
Nuclei
9 CVEs
4.5% of CVEs· 92nd percentile
ExploitDB
2 CVEs
1.0% of CVEs· 82nd percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by SolarWinds as a CNA.
Media Mentions
Media articles that mention a CVE ID published by SolarWinds as a CNA — matched by CVE ID, not by organization name.