FAIL › dossier
SolarWinds
VENDOR· dossier confidence 80%
SolarWinds, a major IT management software vendor, has a concerning history of significant security vulnerabilities, including remote code execution and authentication bypasses, leading to the SEC dropping a lawsuit related to the 2020 SUNBURST breach. Their products have repeatedly demonstrated weaknesses, requiring substantial improvements to security posture and development processes. This history raises serious concerns for organizations relying on SolarWinds products within their critical infrastructure.
SolarWinds has a history of significant security failures, demonstrating a pattern of vulnerabilities in its products. These failures have resulted in remote code execution, data access, and authentication bypasses, indicating a need for improved security practices and product development.
- Critical RCE vulnerability in SolarWinds Serv-U
- Remote command execution via untrusted data deserialization in Web Help Desk
- Hardcoded credential vulnerability in Web Help Desk
- Path traversal vulnerability in Serv-U
- Improper input validation leading to query manipulation
- Privilege escalation via sudo misconfiguration
- Authentication bypass vulnerability in Orion API
- Service crashes via crafted POST requests
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2021-35211 | critical | SolarWinds Serv-U contained a memory escape vulnerability enabling remote code execution and was actively exploited in the wild, linked to ransomware activity. |
| 2026-03-09 | CVE-2025-26399 | high | SolarWinds Web Help Desk allows remote command execution via untrusted data deserialization in AjaxProxy. |
| 2024-10-15 | CVE-2024-28987 | high | SolarWinds Web Help Desk allows remote unauthenticated access via hardcoded credentials, enabling data modification. |
| 2024-08-15 | CVE-2024-28986 | high | SolarWinds Web Help Desk allows remote code execution via deserialization of untrusted data, a high-severity vulnerability actively exploited in the wild. |
| 2022-01-21 | CVE-2021-35247 | high | SolarWinds Serv-U versions 15.2.5 and earlier suffer from improper input validation allowing attackers to send unsanitized queries. |
| 2021-11-03 | CVE-2020-10148 | high | SolarWinds Orion API authentication bypass allowed remote attackers to execute arbitrary commands without valid credentials. |
| 2026-02-12 | CVE-2025-40536 | high | SolarWinds Web Help Desk unpatched RCE |
| 2026-02-03 | CVE-2025-40551 | high | SolarWinds Web Help Desk RCE due to untrusted data deserialization |
| 2021-11-03 | CVE-2016-3643 | high | A sudo misconfiguration in SolarWinds Virtualization Manager allowed privilege escalation. |
| 2024-07-17 | CVE-2024-28995 | high | SolarWinds Serv-U allows remote attackers to read sensitive files via a path traversal vulnerability. |
| 2026-06-05 | CVE-2026-28318 | high | SolarWinds Serv-U allows unauthenticated service crashes via crafted POST requests with a specific Content-Encoding header. |
"SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands."
"SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo."
"SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution."
- Top 50 Engineering Consultancy Companies in the World (2026 ... · dmc-education.com
- Fermi (FRMI) Company Profile & Description - Stock Analysis · stockanalysis.com
- Solarwinds Corp (SWI.US) Share Price · shareprices.com
- Worldwide software supply chain attacks tracker (updated daily) · www.comparitech.com
- SEC Drops SolarWinds Lawsuit Over 2020 SUNBURST Breach · dailysecurityreview.com
- Cybersecurity Incidents Lead to New Standards, Requirements · www.securityindustry.org
- SolarWinds Fixes Critical Serv-U Vulnerabilities Enabling Remote Code ... · dailysecurityreview.com
- Service Desk 2026 release notes - documentation.solarwinds.com · documentation.solarwinds.com
- CERT Vulnerability Notes Database · www.kb.cert.org