SolarWinds maintains a moderately broad portfolio of widely deployed infrastructure management, remote-access, and identity-governance platforms that serve enterprises and managed service providers, positioning its products as high-value targets across networked environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting both the administrative privileges these platforms command and their internet-facing attack surface. The exposure recurs across flagship products including the Orion Platform, Serv-U file-transfer suite, and Access Rights Manager, and concentrates in weakness classes including cross-site scripting, path traversal, deserialization of untrusted data, and improper input validation—patterns typical of web-facing applications handling privileged operations and file access. Defenders should treat SolarWinds disclosures as broadly applicable to infrastructure visibility and access control; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by SolarWinds over time
Of all the CVEs published by SolarWinds as a CNA, 89.9% affect products that SolarWinds develops as a vendor.
Of all the CVEs published that affect products developed by SolarWinds, 56.1% are self-published by SolarWinds as a CNA.
Signals from CVEs in this vendor scope (319 CVEs).
319 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40551CRITICAL SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to r | Jan 28, 2026 | 9.8 | 98 | YES | YES |
CVE-2025-40536CRITICAL SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain | Jan 28, 2026 | 9.8 | 98 | YES | YES |
CVE-2024-28987CRITICAL The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify da | Aug 21, 2024 | 9.1 | 98 | YES | YES |
CVE-2024-28995HIGH SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. | Jun 6, 2024 | 7.5 | 98 | YES | YES |
CVE-2024-28986CRITICAL SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on th | Aug 13, 2024 | 9.8 | 97 | YES | YES |
CVE-2020-10148CRITICAL The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to b | Dec 29, 2020 | 9.8 | 97 | YES | YES |
CVE-2025-26399CRITICAL SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker | Sep 23, 2025 | 9.8 | 96 | YES | NO |
CVE-2021-35211CRITICAL Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may b | Jul 14, 2021 | 10.0 | 95 | YES | NO |
CVE-2009-4006HIGH Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbi | Nov 20, 2009 | 10.0 | 86 | NO | YES |
CVE-2024-0692HIGH The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, result | Mar 1, 2024 | 8.8 | 85 | NO | YES |
Signals from CVEs in this vendor scope (319 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by SolarWinds.
Media articles that mention a CVE ID that affects a product developed by SolarWinds — matched by CVE ID, not by vendor name.