SolarWinds

SolarWinds

Top 100K site
Partial Safe Harbor

Program Details

Handle
solarwindsvdp

In-Scope Domains

  • solarwinds.com

Known Exploited Vulnerabilities 11CVEs

2 linked to ransomware campaigns

  • CVE-2026-28318Serv-UJun 5, 202640.0% EPSS

    SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.

  • CVE-2025-26399Web Help DeskMar 9, 202689.5% EPSS

    SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

  • CVE-2025-40536Web Help DeskFeb 12, 202681.6% EPSS

    SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.

  • CVE-2025-40551Web Help DeskFeb 3, 202683.6% EPSS

    SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

  • CVE-2024-28987Web Help DeskOct 15, 202493.2% EPSS

    SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.

  • CVE-2024-28986Web Help DeskAug 15, 202484.6% EPSS

    SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.

  • CVE-2024-28995Serv-UJul 17, 202499.6% EPSS

    SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.

  • CVE-2021-35247Serv-UJan 21, 20223.5% EPSS

    SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.

  • CVE-2020-10148OrionNov 3, 202192.0% EPSS

    SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

  • CVE-2021-35211Serv-UNov 3, 202191.2% EPSS

    SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.

and 1 more - view full CISA catalog →

Security

Preferred Languages
en

Additional Info

Hiring
Actively hiring security researchers