Skip to content
SolarWinds logo

SolarWinds in the Media

18 mentions across press, blogs, and newsletters

May 2026

April 2026

March 2026

watchTowr Labs

The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)

SolarWinds. Ivanti. SysAid. ManageEngine. Giants of the KEV world, all of whom have ITSM side-projects. ITSMs, as a group of solutions, have played pivotal roles in numerous ransomware gang campaigns - not only do they represent code running on a system, but they hold a significant amount

Mar 18, 2026
Beta News

77 percent of IT teams don’t have full visibility across all their systems

A new report from SolarWinds looks at how IT teams are navigating increasingly fragmented hybrid environments, and in turn, how AI is reshaping modern observability. It finds 77 percent of IT professionals say they have limited visibility across on-prem and cloud environments. In addition 75 percent

Mar 13, 2026
The Record

CISA shortens patch deadline for critical Ivanti, SolarWinds bugs

The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal civilian agencies until Thursday to patch CVE-2025-26399 — a critical vulnerability impacting the popular SolarWinds Web Help Desk.

Mar 10, 2026
SecurityWeek

Recent Ivanti Endpoint Manager Flaw Exploited in Attacks

CISA has added the high-severity authentication bypass vulnerability to its KEV list, along with SolarWinds and Workspace One bugs. The post Recent Ivanti Endpoint Manager Flaw Exploited in Att

Mar 10, 2026
Security Affairs

U.S. CISA adds Ivanti EPM, SolarWinds, and Omnissa Workspace One flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds EPM, SolarWinds, and Omnissa Workspace One flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulner

Mar 10, 2026
The Hacker News

CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability list is as follows - CVE-2021-22054 (CVSS score: 7.5) - A server-side request forge

Mar 10, 2026
The Stack

Help! SolarWinds Web Help Desk is being exploited in the wild again

Someone should probably raise a ticket.

Mar 9, 2026

February 2026

watchTowr Labs

Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))

It’s been a while, but we’re back - in time for story time.Gather round, strap in, and prepare for another depressing journey of “all we wanted to do was reproduce an N-day, and here we are with 0-days”.Today, friends, we’re

Feb 25, 2026
SecurityWeek

SolarWinds Patches Four Critical Serv-U Vulnerabilities

The four security defects could be exploited for remote code execution but require administrative privileges. The post SolarWinds Patches Four Critical Serv-U Vulnerabilities appeared first

Feb 25, 2026
GBHackers

Critical SolarWinds Serv-U Vulnerabilities Enable Remote Root Access

SolarWinds has released a critical security update for its Serv-U file transfer software, patching four vulnerabilities that could allow attackers to execute arbitrary code with root-level privileges on affected servers. All four flaws carry a CVSS score of 9.1, placing them squarely in the Criti

Feb 25, 2026
TechRadarTech Media

SolarWinds Serv-U has some critical security flaws, so users should update now or face attack

Four critical flaws were addressed, all of which could lead to remote code execution.

Feb 25, 2026
The Hacker News

SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution

SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if successfully exploited, could result in remote code execution. The vulnerabilities, all rated 9.1 on the CVSS scoring system, are listed below - CVE-2025-40538 - A broken access con

Feb 25, 2026
CSO Online

New Serv-U bugs extend SolarWinds’ run of high-severity disclosures

Solar

Feb 25, 2026
Security Affairs

SolarWinds patches four critical Serv-U flaws enabling root access

SolarWinds addressed four critical Serv-U vulnerabilities that could let attackers gain root access to unpatched servers. SolarWinds released updates fixing four critical Serv-U vulnerabilities that allow remote code execution, potentially giving attackers full root access on unpatched servers. Serv

Feb 24, 2026
The Register AI-ML

Patch these 4 critical, make-me-root SolarWinds bugs ASAP

SolarWinds + file transfer software = what attackers' dreams are made of If you run SolarWinds’ Serv-U, you should patch promptly. Four critical vulnerabilities in the file transfer software can allow attackers to execute code as root.…

Feb 24, 2026
BleepingComputer

Critical SolarWinds Serv-U flaws offer root access to servers

SolarWinds has patched four critical Serv-U remote code execution vulnerabilities that could grant attackers root access to unpatched servers. [...]

Feb 24, 2026

Toolradar Research

See SolarWinds in context: The SaaS Press Index 2026

We analyzed 6,704 press mentions across 290 outlets to rank which SaaS tools win coverage. Find SolarWinds's position relative to the 488 most-covered tools.

Read the report