<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — SolarWinds</title><description>Vulnerabilities and incidents in SolarWinds products, including Access Rights Manager (ARM), Web Help Desk, Serv-U, and the Orion platform. SolarWinds manages privileged access and IT infrastructure at scale, making its products recurring targets for threat actors. Combined article + CVE feed for the SolarWinds beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>SolarWinds ARM Hard-Coded Key Allows Unauthenticated RCE</title><link>https://0daynews.com/articles/2026-09-20-solarwinds-arm-cve-2026-28326-hardcoded-key-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-09-20-solarwinds-arm-cve-2026-28326-hardcoded-key-rce/</guid><description>CVE-2026-28326 (CVSS 8.8) in SolarWinds Access Rights Manager through 2026.2 lets unauthenticated attackers execute code. Patch ARM 2026.2.1 is available now.</description><pubDate>Sun, 20 Sep 2026 04:30:00 GMT</pubDate><category>SolarWinds</category><category>article</category></item><item><title>CVE-2016-3643 — SolarWinds Virtualization Manager Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2016-3643/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-3643/</guid><description>SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>high</category><category>cve</category></item><item><title>CVE-2020-10148 — SolarWinds Orion Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2020-10148/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-10148/</guid><description>SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-35211 — SolarWinds Serv-U Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-35211/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-35211/</guid><description>SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-35247 — SolarWinds Serv-U Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2021-35247/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-35247/</guid><description>SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>medium</category><category>cve</category></item><item><title>CVE-2024-28986 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2024-28986/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-28986/</guid><description>SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-28987 — SolarWinds Web Help Desk Hardcoded Credential Vulnerability</title><link>https://0daynews.com/cve/cve-2024-28987/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-28987/</guid><description>SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-28995 — SolarWinds Serv-U Path Traversal Vulnerability </title><link>https://0daynews.com/cve/cve-2024-28995/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-28995/</guid><description>SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>high</category><category>cve</category></item><item><title>CVE-2025-26399 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2025-26399/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-26399/</guid><description>SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-40536 — SolarWinds Web Help Desk Security Control Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2025-40536/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-40536/</guid><description>SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>high</category><category>cve</category></item><item><title>CVE-2025-40551 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2025-40551/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-40551/</guid><description>SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-28318 — SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability</title><link>https://0daynews.com/cve/cve-2026-28318/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-28318/</guid><description>SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>high</category><category>cve</category></item><item><title>CVE-2026-28326 — SolarWinds ARM hard-coded key enables unauthenticated RCE</title><link>https://0daynews.com/cve/cve-2026-28326/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-28326/</guid><description>Hard-coded static key in SolarWinds Access Rights Manager through 2026.2 lets unauthenticated attackers execute arbitrary code remotely. Fixed in ARM 2026.2.1.</description><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><category>SolarWinds</category><category>high</category><category>cve</category></item></channel></rss>