Vendor

SolarWinds

As of , 11 SolarWinds vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 4 were added in 2026. Patch first: CVE-2025-26399.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2025-26399Deserialization of Untrusted DataSolarWinds Web Help DeskPatch nowRansomware use, listed within a year0.90
2CVE-2025-40536Security Control BypassSolarWinds Web Help DeskPatch this weekMetasploit module; EPSS 0.740.74
3CVE-2025-40551Deserialization of Untrusted DataSolarWinds Web Help DeskPatch this weekMetasploit module; EPSS 0.840.84
4CVE-2024-28987Hardcoded CredentialSolarWinds Web Help DeskPatch this weekMetasploit module; EPSS 0.930.93
5CVE-2024-28995Path TraversalSolarWinds Serv-UPatch this weekMetasploit module; EPSS 0.990.99
6CVE-2024-28986Deserialization of Untrusted DataSolarWinds Web Help DeskPatch this weekEPSS 0.850.85
7CVE-2020-10148Authentication BypassSolarWinds OrionPatch this weekEPSS 0.920.92
8CVE-2021-35211Remote Code ExecutionSolarWinds Serv-UPatch this weekRansomware use; EPSS 0.910.91
9CVE-2016-3643Privilege EscalationSolarWinds Virtualization ManagerPatch soon0.04
10CVE-2021-35247Improper Input ValidationSolarWinds Serv-UPatch soon0.03
11CVE-2026-28318Uncontrolled Resource ConsumptionSolarWinds Serv-UPatch soon0.02

Products

Added each year

12342021: 3320212022: 1120222023: nonenone20232024: 3320242025: nonenone20252026: 442026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20213
20221
2023none
20243
2025none
20264

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-26399 SolarWinds Web Help DeskRansomware use: Unknown to Known.

Every change we recorded