Product of SolarWinds

Serv-U

As of , 4 SolarWinds Serv-U vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2024-28995.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2024-28995Path TraversalSolarWinds Serv-UPatch this weekMetasploit module; EPSS 0.990.99
2CVE-2021-35211Remote Code ExecutionSolarWinds Serv-UPatch this weekRansomware use; EPSS 0.910.91
3CVE-2021-35247Improper Input ValidationSolarWinds Serv-UPatch soon0.03
4CVE-2026-28318Uncontrolled Resource ConsumptionSolarWinds Serv-UPatch soon0.02

Added each year

0.512021: 1120212022: 1120222023: nonenone20232024: 1120242025: nonenone20252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20211
20221
2023none
20241
2025none
20261

Used in ransomware