Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · solarwinds

solarwinds

· 55 Critical

Total CVEs

332

Critical

55

Products

57

Search All CVEs →

332

Products (57)

serv-u54 CVEsorion platform49 CVEsaccess rights manager32 CVEssolarwinds platform27 CVEsserv-u file server20 CVEsweb help desk20 CVEsserv-u ftp server11 CVEsdatabase performance analyzer10 CVEsorion network performance monitor9 CVEsn-central9 CVEsnetwork performance monitor8 CVEsobservability self-hosted8 CVEsnetwork configuration manager7 CVEsdameware mini remote control7 CVEstftp server6 CVEswebhelpdesk6 CVEslog and event manager5 CVEskiwi syslog server5 CVEssecurity event manager4 CVEsorion web performance monitor4 CVEslog \& event manager3 CVEsstorage manager3 CVEspatch manager3 CVEsvirtualization manager3 CVEsserver and application monitor3 CVEskiwi cattools2 CVEsftp voyager2 CVEsnetpath2 CVEsserv-u mft server2 CVEssftp\/scp server2 CVEsorion netflow traffic analyzer1 CVEsorion network configuration manager1 CVEsnetwork performance monitor orion platform 2018 npm1 CVEsnetwork performance monitor orion platform 2018 netpath1 CVEsorion server and application manager1 CVEsorion user device tracker1 CVEsorion voip \& network quality manager1 CVEsnetwork configuration monitor1 CVEsn-able n-central1 CVEspingdom1 CVEsmanaged service provider patch management engine1 CVEsip address manager web interface1 CVEshelp desk1 CVEsfirewall security manager1 CVEsserv-u managed file transfer1 CVEsbackup profiler1 CVEsengineer\'s toolset1 CVEsadvanced monitoring agent1 CVEsdynamips1 CVEssql sentry1 CVEsdatabase performance monitor1 CVEsstorage profiler1 CVEsstorage resource monitor1 CVEsdameware remote support1 CVEsdameware1 CVEsorion ip address manager1 CVEsorion job scheduler1 CVEs

Recent Vulnerabilities

View all 332
CVE-2026-28321CRITICAL 9.1

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.

CVE-2026-28317CRITICAL 9.1

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.

CVE-2026-28316CRITICAL 9.1

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.

CVE-2026-28315MEDIUM 6.2

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.

CVE-2026-28314CRITICAL 9.1

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.

CVE-2026-28313CRITICAL 9.1

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.

CVE-2026-28312CRITICAL 9.1

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.

CVE-2026-28310CRITICAL 9.1

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.

CVE-2026-28309CRITICAL 9.1

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.

CVE-2026-28308CRITICAL 9.1

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.

CVE-2026-28307CRITICAL 9.1

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.

CVE-2026-28306CRITICAL 9.1

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.

CVE-2026-28305CRITICAL 9.1

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.

CVE-2026-28304CRITICAL 9.1

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.

CVE-2026-28302CRITICAL 9.1

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.

CVE-2018-25252MEDIUM 6.2

FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP field to trigger a buffer overflow that crashes the FTP Voyager process.

CVE-2026-28298MEDIUM 5.9

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.

CVE-2026-28297MEDIUM 6.1

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.

CVE-2025-40541CRITICAL 9.1

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

CVE-2025-40540CRITICAL 9.1

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

CVE-2025-40539CRITICAL 9.1

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

CVE-2025-40538CRITICAL 9.1

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

CVE-2025-40554CRITICAL 9.8

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

CVE-2025-40553CRITICAL 9.8

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

CVE-2025-40552CRITICAL 9.8

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.