Known Vulnerabilities for products from SolarWinds

Listed below are 20 of the newest known vulnerabilities associated with the vendor "SolarWinds".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-28322 json Not Provided 2026-06-30 2026-07-02
CVE-2026-28321 json SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which ... Not Provided 2026-07-21 2026-07-24
CVE-2026-28318 json SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication usin... Not Provided 2026-06-04 2026-07-22
CVE-2026-28317 json Not Provided 2026-07-21 2026-07-24
CVE-2026-28316 json SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalati... Not Provided 2026-07-21 2026-07-24
CVE-2026-28315 json SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijackin... Not Provided 2026-07-21 2026-07-24
CVE-2026-28314 json Not Provided 2026-07-21 2026-07-24
CVE-2026-28313 json SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking lea... Not Provided 2026-07-21 2026-07-24
CVE-2026-28312 json SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system admini... Not Provided 2026-07-21 2026-07-24
CVE-2026-28310 json SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their us... Not Provided 2026-07-21 2026-07-24
CVE-2026-28309 json SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system ad... Not Provided 2026-07-21 2026-07-24
CVE-2026-28308 json SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execut... Not Provided 2026-07-21 2026-07-24
CVE-2026-28307 json SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an ... Not Provided 2026-07-21 2026-07-24
CVE-2026-28306 json SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their pri... Not Provided 2026-07-21 2026-07-24
CVE-2026-28305 json SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execut... Not Provided 2026-07-21 2026-07-24
CVE-2026-28304 json SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary executio... Not Provided 2026-07-21 2026-07-24
CVE-2026-28302 json SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalati... Not Provided 2026-07-21 2026-07-24
CVE-2026-28299 json SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the ... Not Provided 2026-06-02 2026-07-22
CVE-2026-28298 json SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when expl... Not Provided 2026-03-26 2026-03-31
CVE-2026-28297 json SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when expl... Not Provided 2026-03-26 2026-03-31

Known software with vulnerabilities from SolarWinds

Type Vendor Product Version
ApplicationSolarwindsAdvanced Monitoring Agent-
ApplicationSolarwindsAdvanced Subnet Calculator9.1
ApplicationSolarwindsCollector2.2.1.0
ApplicationSolarwindsDameware12.1
ApplicationSolarwindsDameware Mini Remote Control12.0
ApplicationSolarwindsDameware Mini Remote Control Client Agent Service6.9.0.0
ApplicationSolarwindsDameware Remote Support10.0
ApplicationSolarwindsDamewire Mini Remote Control10.0
ApplicationSolarwindsDatabase Performance Analyzer11.1.457
ApplicationSolarwindsEngineers Editionsolarwinds_engineers_edition
ApplicationSolarwindsExchange Monitor1.0.1.30
ApplicationSolarwindsFirewall Security Manager6.6.5
ApplicationSolarwindsFtp Voyager16.2.0
ApplicationSolarwindsInformation Service2.5.1
ApplicationSolarwindsIntegrated Virtual Infrastructure Monitor1.1.674.0
ApplicationSolarwindsIpmonitor10.0.1368.1
ApplicationSolarwindsIp Address Manager Web Interface3.0
ApplicationSolarwindsJob Engine1.5.2.0
ApplicationSolarwindsKiwi Cattools3.6.0__\(service_edition\)
ApplicationSolarwindsLog And Event Manager6.1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report