solarwinds has 5 CVEs on record between 2025 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 9.1 (critical), with 3 rated critical. 20% have been exploited in the wild — well above the 1% corpus average, so solarwinds flaws are worth patching on sight. Most affected products: Observability Self-Hosted (2), Access Rights Manager (1), Web Help Desk (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 20% vs 1% corpus
- Median CVSS
- 9.1
- Publish → KEV
- —(1)
- Last 90 days
- 3 prev 0
Products
- Observability Self-Hosted 2
- Access Rights Manager 1
- Web Help Desk 1
- serv-u 1
Worst active — by depth score
CVE-2025-40551Critical· 9.8SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability96CVE-2026-28326High· 8.8SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability61CVE-2026-28324Critical· 9.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks54CVE-2025-40548Critical· 9.1A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code50CVE-2026-28325High· 8.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.49
solarwinds vulnerabilities
CVEs affecting solarwinds, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-28325High· 8.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
CVE-2026-28324Critical· 9.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are …
CVE-2026-28326High· 8.8PoCSolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
CVE-2025-40551Critical· 9.8CISA KEVPoCSolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited …
CVE-2025-40548Critical· 9.1A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code
A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the ri…