Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Solarwinds

31 known vulnerabilities

23
CRITICAL
4
HIGH
4
MEDIUM

Top Products

serv-u 20 web help desk 8 observability self-hosted 2 ftp voyager 1
31 CVEs
9.8
CVE-2026-28323

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2

9.1
CVE-2026-28321

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, w

9.1
CVE-2026-28317

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc

9.1
CVE-2026-28316

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc

6.2
CVE-2026-28315

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hij

9.1
CVE-2026-28314

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. Us

9.1
CVE-2026-28313

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijackin

9.1
CVE-2026-28312

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system adm

9.1
CVE-2026-28310

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate the

9.1
CVE-2026-28309

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create syst

9.1
CVE-2026-28308

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e

9.1
CVE-2026-28307

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated int

9.1
CVE-2026-28306

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate thei

9.1
CVE-2026-28305

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e

9.1
CVE-2026-28304

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary exe

9.1
CVE-2026-28302

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc

7.5
CVE-2026-28318 KEV

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication

8.2
CVE-2026-28299

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause

6.2
CVE-2018-25252

FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by in

5.9
CVE-2026-28298

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when

6.1
CVE-2026-28297

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when

9.1
CVE-2025-40541

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor

9.1
CVE-2025-40540

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb

9.1
CVE-2025-40539

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arb

9.1
CVE-2025-40538

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to crea

9.8
CVE-2025-40554

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could

9.8
CVE-2025-40553

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead

9.8
CVE-2025-40552

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would

9.8
CVE-2025-40551 KEV

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead

7.5
CVE-2025-40537

SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situat

8.1
CVE-2025-40536 KEV

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could

Frequently Asked Questions

How many CVEs affect Solarwinds?

Solarwinds has 31 CVE records in our database, including 23 critical and 4 high severity vulnerabilities. 3 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Solarwinds vulnerabilities?

Solarwinds has 23 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. 3 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Solarwinds vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Solarwinds products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Solarwinds Vulnerabilities

CyberStrike scans your infrastructure for Solarwinds vulnerabilities and provides real-time remediation guidance.

Get Started