Vendor scorecard
SolarWinds
SolarWinds security disclosure record — CVE volume, CVSS severity mix and product-category breakdown, sourced from the NIST NVD.
CPE: solarwinds
Product families
2
Open in latest
46
Inferred — see methodology
Last disclosure
Jul 21, 2026
01
Product categories
2 trackedCVE volume, severity mix and the inferred latest shipping version per category.
| Category | CVEs | Volume | Severity mix | Open | Inferred latest |
|---|---|---|---|---|---|
| Serv-UNetwork Management & Monitoringserv-u | 41 | 11 | 2026.3HIGH | ||
| Orion / Network Performance MonitorNetwork Management & Monitoringorion_platform, network_performance_monitor, network_configuration_manager | 40 | 35 | 2023.4MED |
02
Recent CVEs
12 shownMost recently published, newest first. Each ID links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-28321(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations. | Jul 21, 2026 |
| CVE-2026-28317(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments. | Jul 21, 2026 |
| CVE-2026-28316(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments. | Jul 21, 2026 |
| CVE-2026-28315(opens NVD record) | Medium | 6.2 | SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account. | Jul 21, 2026 |
| CVE-2026-28314(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. | Jul 21, 2026 |
| CVE-2026-28313(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments. | Jul 21, 2026 |
| CVE-2026-28312(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments. | Jul 21, 2026 |
| CVE-2026-28310(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments. | Jul 21, 2026 |
| CVE-2026-28309(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments. | Jul 21, 2026 |
| CVE-2026-28308(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments. | Jul 21, 2026 |
| CVE-2026-28307(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments. | Jul 21, 2026 |
| CVE-2026-28306(opens NVD record) | Critical | 9.1 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments. | Jul 21, 2026 |
81 CVEs · 2 product families