Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

SolarWinds

First CVE: Feb 16, 2001Active for: 25 yearsTotal CVEs: 319
72.3
VTI Score
TOP TARGET

SolarWinds maintains a moderately broad portfolio of widely deployed infrastructure management, remote-access, and identity-governance platforms that serve enterprises and managed service providers, positioning its products as high-value targets across networked environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting both the administrative privileges these platforms command and their internet-facing attack surface. The exposure recurs across flagship products including the Orion Platform, Serv-U file-transfer suite, and Access Rights Manager, and concentrates in weakness classes including cross-site scripting, path traversal, deserialization of untrusted data, and improper input validation—patterns typical of web-facing applications handling privileged operations and file access. Defenders should treat SolarWinds disclosures as broadly applicable to infrastructure visibility and access control; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
319
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
3.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by SolarWinds over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2001
25 years ago
Most Recent CVE
Jun 4, 2026
50 days ago

Self-Reporting Analysis

Of all the CVEs published by SolarWinds as a CNA, 89.9% affect products that SolarWinds develops as a vendor.

89.9%
10.1%
Self-reported: 179 (89.9%)
Third-party: 20 (10.1%)

Of all the CVEs published that affect products developed by SolarWinds, 56.1% are self-published by SolarWinds as a CNA.

56.1%
43.9%
Self-published: 179 (56.1%)
Other CNAs: 140 (43.9%)

Products(57 total)

Top CVEs

Signals from CVEs in this vendor scope (319 CVEs).

319 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-40551CRITICAL
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to r
Jan 28, 20269.898YESYES
CVE-2025-40536CRITICAL
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain
Jan 28, 20269.898YESYES
CVE-2024-28987CRITICAL
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify da
Aug 21, 20249.198YESYES
CVE-2024-28995HIGH
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
Jun 6, 20247.598YESYES
CVE-2024-28986CRITICAL
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on th
Aug 13, 20249.897YESYES
CVE-2020-10148CRITICAL
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to b
Dec 29, 20209.897YESYES
CVE-2025-26399CRITICAL
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker
Sep 23, 20259.896YESNO
CVE-2021-35211CRITICAL
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may b
Jul 14, 202110.095YESNO
CVE-2009-4006HIGH
Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbi
Nov 20, 200910.086NOYES
CVE-2024-0692HIGH
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, result
Mar 1, 20248.885NOYES
View all 319 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products319 CVEs
40%
45%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local33 (10.3%)
Network200 (62.7%)
Unknown43 (13.5%)
Physical0 (0.0%)
Adjacent Network43 (13.5%)
Attack Complexity
Low266 (83.4%)
High10 (3.1%)
Unknown43 (13.5%)
User Interaction
None211 (66.1%)
Unknown43 (13.5%)
Required65 (20.4%)
Privileges Required
Low115 (36.1%)
High52 (16.3%)
None109 (34.2%)
Unknown43 (13.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (319 CVEs).

CISA KEV
11 CVEs
3.4% of CVEs· 99th percentile
Metasploit
15 CVEs
4.7% of CVEs· 98th percentile
Nuclei
11 CVEs
3.4% of CVEs· 95th percentile
ExploitDB
31 CVEs
9.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by SolarWinds.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by SolarWinds — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For SolarWinds's Products

View all 6 CNAs →

Top CWEs