Skip to content
eastbaycyber

SolarWinds: CISA KEV History

Every SolarWinds vulnerability in the CISA Known Exploited Vulnerabilities catalog: confirmed in-the-wild exploitation, addition timeline, and ransomware linkage. Rebuilt automatically on every site deploy.

Snapshot: 2026-09-08 · Source: CISA KEV Catalog · Full KEV dashboard

KEV entries
11
Added, last 12 months
4
Ransomware-linked
2
Latest addition
2026-06-05

SolarWinds KEV additions per month, last 24 months

2024-10: 1 added124/102024-11: 0 added2024-12: 0 added2025-01: 0 added25/012025-02: 0 added2025-03: 0 added2025-04: 0 added25/042025-05: 0 added2025-06: 0 added2025-07: 0 added25/072025-08: 0 added2025-09: 0 added2025-10: 0 added25/102025-11: 0 added2025-12: 0 added2026-01: 0 added26/012026-02: 2 added22026-03: 1 added12026-04: 0 added26/042026-05: 0 added2026-06: 1 added12026-07: 0 added26/072026-08: 0 added2026-09: 0 added

Most-listed products: Web Help Desk, Serv-U, Orion, Virtualization Manager.

Latest 11 of 11 SolarWinds KEV entries

CVEVulnerabilityAddedRansomware
CVE-2026-28318SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability2026-06-05No
CVE-2025-26399SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability2026-03-09Yes
CVE-2025-40536SolarWinds Web Help Desk Security Control Bypass Vulnerability2026-02-12No
CVE-2025-40551SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability2026-02-03No
CVE-2024-28987SolarWinds Web Help Desk Hardcoded Credential Vulnerability2024-10-15No
CVE-2024-28986SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability2024-08-15No
CVE-2024-28995SolarWinds Serv-U Path Traversal Vulnerability 2024-07-17No
CVE-2021-35247SolarWinds Serv-U Improper Input Validation Vulnerability2022-01-21No
CVE-2020-10148SolarWinds Orion Authentication Bypass Vulnerability2021-11-03No
CVE-2021-35211SolarWinds Serv-U Remote Code Execution Vulnerability2021-11-03Yes
CVE-2016-3643SolarWinds Virtualization Manager Privilege Escalation Vulnerability2021-11-03No

CVE links go to our explainer when one exists, otherwise to the NVD record.

Data: official CISA KEV catalog, fetched at build time. Figures may be reused with attribution to East Bay Cyber and CISA. See also the KEV Velocity Dashboard and all tracked vendors.