SolarWinds known exploited vulnerabilities
CISA lists 11 SolarWinds CVEs as exploited in the wild. 4 were added in the last 12 months (latest 2026-06-05), and 2 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2024-28995 (Serv-U): EPSS 99.6%, added 2024-07-17
- CVE-2024-28987 (Web Help Desk): EPSS 93.3%, added 2024-10-15
- CVE-2020-10148 (Orion): EPSS 92.0%, added 2021-11-03
- CVE-2021-35211 (Serv-U): EPSS 91.2%, added 2021-11-03
- CVE-2025-26399 (Web Help Desk): EPSS 89.5%, added 2026-03-09
Most affected SolarWinds products
Web Help Desk (5), Serv-U (4), Orion (1), Virtualization Manager (1).
All SolarWinds CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-28318 | Serv-U | Serv-U Uncontrolled Resource Consumption | 2026-06-05 | 2026-06-19 | 1.9% | – |
| CVE-2025-26399 | Web Help Desk | Web Help Desk Deserialization of Untrusted Data | 2026-03-09 | 2026-03-12 | 89.5% | Yes |
| CVE-2025-40536 | Web Help Desk | Web Help Desk Security Control Bypass | 2026-02-12 | 2026-02-15 | 73.6% | – |
| CVE-2025-40551 | Web Help Desk | Web Help Desk Deserialization of Untrusted Data | 2026-02-03 | 2026-02-06 | 84.2% | – |
| CVE-2024-28987 | Web Help Desk | Web Help Desk Hardcoded Credential | 2024-10-15 | 2024-11-05 | 93.3% | – |
| CVE-2024-28986 | Web Help Desk | Web Help Desk Deserialization of Untrusted Data | 2024-08-15 | 2024-09-05 | 84.6% | – |
| CVE-2024-28995 | Serv-U | Serv-U Path Traversal | 2024-07-17 | 2024-08-07 | 99.6% | – |
| CVE-2021-35247 | Serv-U | Serv-U Improper Input Validation | 2022-01-21 | 2022-02-04 | 3.5% | – |
| CVE-2021-35211 | Serv-U | Serv-U Remote Code Execution | 2021-11-03 | 2021-11-17 | 91.2% | Yes |
| CVE-2020-10148 | Orion | Orion Authentication Bypass | 2021-11-03 | 2022-05-03 | 92.0% | – |
| CVE-2016-3643 | Virtualization Manager | Virtualization Manager Privilege Escalation | 2021-11-03 | 2022-05-03 | 3.7% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors