Skip to content
Threat Feed

Vendor

SolarWinds

15 briefs RSS
high advisory

SolarWinds Web Help Desk Security Bypass Vulnerability

A vulnerability in SolarWinds Web Help Desk, identified as CVE-2024-28986, allows remote unauthenticated attackers to bypass security measures, potentially leading to unauthorized access.

Web Help Desk web-application security-bypass vulnerability-management
1c
critical advisory

SolarWinds Web Help Desk SAML Authentication Bypass

SolarWinds Web Help Desk versions 2026.1 and prior are vulnerable to a critical authentication bypass via the SAML 2.0 implementation, allowing unauthenticated remote access.

Web Help Desk authentication-bypass saml vulnerability cve-2026-28323
1t 1c
high advisory

SolarWinds Serv-U: Multiple Critical Vulnerabilities

A remote, highly privileged attacker can exploit multiple vulnerabilities in SolarWinds Serv-U to execute arbitrary code as Root, gain administrator privileges, take over accounts, disclose confidential information, or perform Cross-Site Scripting attacks.

Serv-U vulnerability rce xss data-exfiltration
7t
critical advisory

SolarWinds Serv-U Privilege Escalation Vulnerability (CVE-2026-28310)

CVE-2026-28310 describes a critical privilege escalation vulnerability (CVSS 9.1) affecting SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing a domain administrator to elevate their user type to that of a system administrator, with lower impact noted in Windows deployments.

Serv-U 15.5.4 HF1 and below privilege-escalation server-software vulnerability
1t 1c 2i
critical advisory

Remote Code Execution Vulnerability in SolarWinds Serv-U (CVE-2026-28304)

A critical remote code execution vulnerability (CVE-2026-28304) has been identified in SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing an attacker with high privileges to execute arbitrary code remotely as root, posing a severe risk to affected systems, though with lower impact on Windows deployments.

Serv-U +1 remote-code-execution privilege-escalation vulnerability-exploitation vulnerability cve improper-access-control server software-update +5
5t 8c 3i
critical advisory

SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability Allows Privilege Escalation and RCE

A critical insecure direct object reference (IDOR) vulnerability, CVE-2026-28302, in SolarWinds Serv-U allows authenticated group administrators to achieve privilege escalation and remote code execution as root.

Serv-U +2 idor privilege-escalation rce file-transfer vulnerability solarwinds
3t 4c
critical threat

Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector

The Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.

www.acosol.es +42 Qilin +1 ransomware double-extortion golang agriculture food-production
2r 13t 156i updated
high threat

Suspicious SolarWinds Web Help Desk Java Module Load or Child Process

Detects suspicious behavior related to SolarWinds Web Help Desk, specifically the loading of untrusted native modules (DLLs) or the spawning of suspicious child processes (cmd, PowerShell, rundll32) by the Java process, potentially indicating exploitation of deserialization vulnerabilities CVE-2025-40536 and CVE-2025-40551.

Web Help Desk solarwinds webhelpdesk deserialization cve-2025-40536 cve-2025-40551 remote code execution initial access
2r 1t 2c
medium advisory

AdFind.exe Execution with Reconnaissance Arguments

This rule detects the execution of AdFind.exe with specific command-line arguments used for reconnaissance, often associated with threat actors like Wizard Spider, FIN6, and groups linked to SUNBURST, who use it to enumerate domain controllers.

AdFind +2 Conti +3 active-directory reconnaissance discovery
2r 1t 1i
low advisory

Account Discovery Command via SYSTEM Account

The rule identifies when the SYSTEM account uses an account discovery utility, potentially indicating discovery activity after privilege escalation, focusing on utilities like whoami.exe and net1.exe executed under the SYSTEM account.

Elastic Defend +5 discovery privilege-escalation windows
3r 3t
medium advisory

Suspicious SolarWinds Child Process Execution

Detection of unusual child processes spawned by SolarWinds processes may indicate malicious program execution, potentially bypassing security controls.

Elastic Defend +3 supply-chain execution solarwinds
2r 2t
high threat

SUNBURST Command and Control Activity Detected

This rule detects post-exploitation command and control activity related to the SUNBURST backdoor, which targets SolarWind's Orion software, mimicking the Orion Improvement Program (OIP) protocol for covert communication.

SolarWinds Orion Platform APT29 +5 solarwinds sunburst supply-chain command-and-control
2r 2t
medium advisory

SolarWinds Process Disabling Services via Registry Modification

A SolarWinds binary is modifying the start type of a service to be disabled via registry modification, potentially to disable or impair security services.

Microsoft Defender XDR +1 solarwinds defense-evasion registry-modification supply-chain
2r 3t
medium advisory

Suspicious Shell Execution via Velociraptor

Attackers are abusing the Velociraptor endpoint visibility and response tool to execute shell commands (cmd, PowerShell, rundll32) on compromised Windows systems, blending in with legitimate system processes.

SolarWinds Web Help Desk velociraptor command-and-control windows
2r 2t
medium advisory

Suspicious Command Execution via SolarWinds Process

This brief covers the detection of suspicious command execution, specifically Cmd.exe or PowerShell.exe, as child processes of legitimate SolarWinds executables, indicative of potential supply chain compromise and unauthorized command execution on Windows systems.

SolarWinds Orion supply-chain solarwinds command-execution powershell cmd
2r 3t