Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
Conclusion & alert: CVE-2021-35247 is rated Active Exploitation (70.7/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.36%). Core evidence: CISA KEV confirms active exploitation (added 2022-01-21) affecting SolarWinds / Serv-U. a weakness (CWE-20) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: SolarWinds Serv-U Improper Input Validation Vulnerability · CISA KEV detail
: 2022-01-21
: 2022-02-04
: Apply updates per vendor instructions.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 5.34% | 3.36% | -1.99% |
| 2 | 2026-03-22 | 1.83% | 5.34% | +3.51% |
| 3 | 2026-03-21 | — | 1.83% | — |
Full EPSS history (25 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| solarwinds | serv-u | < 15.3 | cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-3_release_notes.htm | Release Notes Vendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247 | Broken Link Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35247 | US Government Resource |