Vulnerabilities
291 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-28323 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2026-28316 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with t SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments. NVD description · AI analysis pending | 9.1 group max | 2% |
| — | ||
| CVE-2026-28318 | Unauthenticated DoS in SolarWinds Serv-U via crafted Content-Encoding: deflate POSTs SolarWinds Serv-U, an FTP and managed-file-transfer server, contains an uncontrolled resource consumption flaw (CWE-400) that allows an unauthenticated remote attacker to exhaust the service's resources. It is triggered by sending specially crafted POST requests with the Content-Encoding: deflate header, which crashes the Serv-U service. An attacker gains denial of service — file transfer operations stop until the service is restarted — and the available data indicates no remote code execution or data exposure. Any organization running Serv-U, typically enterprises using it as an internal or internet-facing file transfer endpoint, is affected; the available advisories do not specify affected version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-05, signaling exploitation in the wild, and EPSS estimates a 40% probability of exploitation within 30 days (99th percentile), though CVSS scoring is pending and no public proof-of-concept is known. Do: Inventory all Serv-U deployments and apply SolarWinds' mitigation per vendor instructions, or discontinue use of the product if mitigations are unavailable, as required by the KEV listing (federal agencies must follow BOD 22-01 timelines). As an interim mitigation, block or normalize POST requests carrying the Content-Encoding: deflate header at a WAF or reverse proxy and restrict Serv-U's internet exposure. Monitor the Serv-U service for crashes, since successful exploitation takes it down until it is restarted. | 7.5 | 40% | KEV |
| moderate≈tens of thousands of installations; only a few thousand Serv-U servers exposed to the internet | |
| CVE-2026-28299 | SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due t SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2018-25252 | FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the s FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP field to trigger a buffer overflow that crashes the FTP Voyager process. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2026-28297 +1 in the same advisory: …28298 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended scrip SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. NVD description · AI analysis pending | 8.7 group max | <1% |
| — | ||
| CVE-2025-40541 | An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2025-40551 | Unauthenticated Deserialization RCE in SolarWinds Web Help Desk SolarWinds Web Help Desk contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to reach the vulnerable functionality over the network and have it deserialize attacker-supplied input. By sending crafted serialized data, the attacker triggers remote code execution and can run arbitrary commands on the host machine running Web Help Desk. Successful compromise grants control of the help desk server, and observed intrusions include attackers installing Zoho agents and Velociraptor for post-exploitation. Any organization running the product is affected, particularly instances exposed to the internet; the flaw carries a CVSS 9.8 (critical) score and federal agencies are under a CISA (BOD 22-01) patching deadline. The vulnerability is being actively exploited in the wild and was added to the CISA KEV catalog on 2026-02-03, with an EPSS probability of 83.6% that it will be exploited within 30 days. Do: Upgrade Web Help Desk to the latest patched release per the SolarWinds security advisory (the source data does not specify a fixed version number), and follow BOD 22-01 mitigations or discontinue use if mitigation is not possible, noting the federal patching deadline. Until patched, restrict internet-facing access to the Web Help Desk server. Check hosts for post-exploitation artifacts reported in the wild, such as unexpected Zoho agent installations and Velociraptor, and review logs for unauthenticated requests targeting the application. | 9.8 group max | 84% | KEV |
| large≈ tens of thousands of on-premises deployments worldwide (order of magnitude: 10,000–100,000 systems), an estimate | |
| CVE-2025-40549 | A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute c A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences in how paths and home directories are handled. NVD description · AI analysis pending | 9.1 | 1% |
| — | ||
| CVE-2025-26391 +1 in the same advisory: …40545 | SolarWinds Observability Self-Hosted XSS Vulnerability. SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account. NVD description · AI analysis pending | 5.4 group max | <1% |
| — | ||
| CVE-2025-26392 | SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege account. NVD description · AI analysis pending | 4.6 | <1% |
| — | ||
| CVE-2025-26399 | Unauthenticated Deserialization RCE in SolarWinds Web Help Desk SolarWinds Web Help Desk contains an unauthenticated deserialization of untrusted data vulnerability (CWE-502) in its AjaxProxy component that allows remote attackers to run arbitrary commands on the host machine without any credentials or user interaction. It is triggered by sending a crafted request to the AjaxProxy endpoint of an affected Web Help Desk installation. Successful exploitation yields full code execution on the server, and the flaw is known to be used in ransomware campaigns. Any organization running SolarWinds Web Help Desk is affected, including installations already patched for the earlier CVE-2024-28988 and CVE-2024-28986, since this flaw is a patch bypass of both. The flaw carries a very high exploitation probability (EPSS ~89.5%) and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09 with known ransomware use. Do: Immediately apply SolarWinds' hotfix for CVE-2025-26399 per the vendor's instructions — organizations that previously patched CVE-2024-28988 or CVE-2024-28986 must apply the new hotfix because those patches do not close this flaw. If the hotfix cannot be applied right away, restrict network access to Web Help Desk (firewall/VPN, limit exposure of the service to the internet) and discontinue use if mitigations are unavailable, per CISA KEV/BOD 22-01 guidance. Given known ransomware use, review Web Help Desk hosts for signs of compromise, including unexpected process execution and accounts or data accessed via the server. | 9.8 | 90% | KEV ransomware |
| moderatelow thousands of internet-exposed Web Help Desk instances, with a total on-prem install base plausibly in the tens of thousands | |
| CVE-2024-28988 | Unauthenticated Java Deserialization RCE in SolarWinds Web Help Desk CVE-2024-28988 is a Java deserialization remote code execution flaw (CWE-502) in SolarWinds Web Help Desk that allows an attacker to run commands on the host machine running the application. It is triggered over the network by sending the application crafted input that is deserialized without adequate validation, and requires no authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N). Successful exploitation gives remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8, critical). All Web Help Desk deployments running versions prior to the vendor's hotfix are affected; the flaw was discovered by the Trend Micro Zero Day Initiative (ZDI) team, which found it exploitable without authentication while researching a previously reported Web Help Desk vulnerability. As of this analysis there is no confirmed in-the-wild exploitation, no CISA KEV listing, and no known public PoC, but EPSS assigns a ~39.4% probability of exploitation within 30 days (99th percentile), so defenders should treat it as a high-priority patch. Do: Apply the hotfix SolarWinds has released for Web Help Desk immediately, per the vendor's advisory, since all customers are urged to patch. If patching is delayed, restrict network access to the Web Help Desk server — especially remove direct internet exposure — and monitor for unexpected command or child-process activity from the Web Help Desk service. Also inventory which of your instances are internet-facing and review their access logs for unauthenticated, suspicious requests. | 9.8 | 39% |
| moderate≈1,000–10,000 internet-exposed Web Help Desk instances (public internet-wide scans); total on-prem install base likely in the low tens of thousands | ||
| CVE-2025-26398 | SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host. NVD description · AI analysis pending | 6.4 | <1% |
| — | ||
| CVE-2025-26400 | SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2025-26397 | SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires authentication from a low-level account and local access to the host server. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-26394 +1 in the same advisory: …26395 | SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required. NVD description · AI analysis pending | 4.8 group max | <1% |
| — | ||
| CVE-2024-45712 | SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-52606 | SolarWinds Platform is affected by server-side request forgery vulnerability. SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of a malicious web request. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2024-28989 | SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software. SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2024-45709 | SolarWinds Web Help Desk was susceptible to a local file read vulnerability. SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited. NVD description · AI analysis pending | 5.5 | <1% |
| — |