CyberMax
Home › Exploited CVEs

SolarWinds known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 11 SolarWinds CVEs as exploited in the wild. 4 were added in the last 12 months (latest 2026-06-05), and 2 are known to be used in ransomware campaigns.

SolarWinds CVEs added to CISA KEV per year
2021: 3202132022: 1202212024: 3202432026: 420264

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected SolarWinds products

Web Help Desk (5), Serv-U (4), Orion (1), Virtualization Manager (1).

All SolarWinds CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-28318Serv-UServ-U Uncontrolled Resource Consumption2026-06-052026-06-191.9%–
CVE-2025-26399Web Help DeskWeb Help Desk Deserialization of Untrusted Data2026-03-092026-03-1289.5%Yes
CVE-2025-40536Web Help DeskWeb Help Desk Security Control Bypass2026-02-122026-02-1573.6%–
CVE-2025-40551Web Help DeskWeb Help Desk Deserialization of Untrusted Data2026-02-032026-02-0684.2%–
CVE-2024-28987Web Help DeskWeb Help Desk Hardcoded Credential2024-10-152024-11-0593.3%–
CVE-2024-28986Web Help DeskWeb Help Desk Deserialization of Untrusted Data2024-08-152024-09-0584.6%–
CVE-2024-28995Serv-UServ-U Path Traversal2024-07-172024-08-0799.6%–
CVE-2021-35247Serv-UServ-U Improper Input Validation2022-01-212022-02-043.5%–
CVE-2021-35211Serv-UServ-U Remote Code Execution2021-11-032021-11-1791.2%Yes
CVE-2020-10148OrionOrion Authentication Bypass2021-11-032022-05-0392.0%–
CVE-2016-3643Virtualization ManagerVirtualization Manager Privilege Escalation2021-11-032022-05-033.7%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors