18 Total CVEs
18 AI Analyzed
4 CISA KEV
15 Critical

Profile

22.2% ended up actively exploited 4 of 18 added to CISA KEV
83% rated critical (CVSS 9.0+) 15 critical, 3 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

15 CVEs in the last 12 months

Products

  • Serv-U5
  • Web Help Desk1

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-18 of 18 CVEs
CVE-2026-28323
Analyzed
9.8
SolarWinds Web Help Desk

SolarWinds Web Help Desk contains a SAML authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access if SAML...

2026-07-31
CVE-2026-28318
KEV Analyzed
9.5
SolarWinds Serv-U

SolarWinds Serv-U is vulnerable to an uncontrolled resource consumption flaw allowing unauthenticated attackers to crash the service via specially cra...

2026-06-06
CVE-2025-40554
Analyzed
9.8
SolarWinds Multiple Products

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke s...

2026-01-28
CVE-2025-40553
Analyzed
9.8
SolarWinds Multiple Products

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic...

2026-01-28
CVE-2025-40552
Analyzed
9.8
SolarWinds Multiple Products

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to exe...

2026-01-28
CVE-2025-40551
KEV Analyzed
9.8
SolarWinds Multiple Products

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic...

2026-01-28
CVE-2025-40549
Analyzed
9.1
SolarWinds Multiple Products

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to...

2025-11-19
CVE-2025-40548
Analyzed
9.1
SolarWinds Multiple Products

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code....

2025-11-19
CVE-2025-40547
Analyzed
9.1
SolarWinds Multiple Products

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute cod...

2025-11-19
CVE-2025-40541
Analyzed
9.1
SolarWinds Serv-U

An Insecure Direct Object Reference (IDOR) vulnerability in Serv-U allows authenticated administrators to execute native code as a privileged account...

2026-02-24
CVE-2025-40540
Analyzed
9.1
SolarWinds Serv-U

A critical type confusion vulnerability in Serv-U allows an authenticated administrative user to execute arbitrary native code, potentially compromisi...

2026-02-24
CVE-2025-40539
Analyzed
9.1
SolarWinds Serv-U

A type confusion vulnerability in Serv-U enables authenticated administrative users to execute arbitrary native code with the privileges of the servic...

2026-02-24
CVE-2025-40538
Analyzed
9.1
SolarWinds Serv-U

A broken access control vulnerability in Serv-U allows domain or group administrators to escalate privileges, create system admin users, and execute a...

2026-02-24
CVE-2025-40537
Analyzed
7.5
SolarWinds Multiple Products

SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to ad...

2026-01-28
CVE-2025-40536
KEV Analyzed
8.1
SolarWinds Multiple Products

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated atta...

2026-01-28
CVE-2025-26399
KEV Analyzed
9.8
SolarWinds Multiple Products

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if expl...

2025-09-23
CVE-2025-26397
Analyzed
7.8
SolarWinds Multiple Products

SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability

2025-07-25
CVE-2024-28988
Analyzed
9.8
SolarWinds Multiple Products

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an...

2025-09-02