Changeflow GovPing Data Privacy & Cybersecurity SolarWinds Platform XSS Vulnerabilities Identified
Priority review Notice Amended Final

SolarWinds Platform XSS Vulnerabilities Identified

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 25th, 2026
Detected March 26th, 2026
Email

Summary

CERT-Bund has issued a security advisory regarding multiple vulnerabilities in the SolarWinds Platform that could allow for Cross-Site Scripting (XSS) attacks. The advisory provides details on affected versions and mitigation strategies. The identified vulnerabilities have a CVSS Base Score of 6.5, rated as medium.

What changed

This advisory from CERT-Bund details multiple vulnerabilities within the SolarWinds Platform (formerly Orion) that attackers can exploit to conduct Cross-Site Scripting (XSS) attacks. The vulnerabilities affect SolarWinds Platform versions prior to 2026.1.1 and have been assigned a CVSS Base Score of 6.5 (medium). The advisory indicates that remote attacks are possible and provides mitigation information.

Organizations utilizing the SolarWinds Platform, particularly those running versions prior to 2026.1.1, should review the advisory and implement available mitigation strategies to protect their systems. This includes assessing the potential impact of these XSS vulnerabilities on their IT infrastructure and user data. While no specific compliance deadline is mentioned, prompt action is recommended to address the security risks.

What to do next

  1. Review CERT-Bund advisory WID-SEC-2026-0869 for affected SolarWinds Platform versions.
  2. Implement available mitigation strategies to address identified XSS vulnerabilities.
  3. Assess potential impact on IT infrastructure and user data.

Source document (simplified)

[WID-SEC-2026-0869] SolarWinds Platform: Mehrere Schwachstellen ermöglichen Cross-Site Scripting CVSS Base Score 6.5 (mittel) CVSS Temporal Score 5.7 (mittel) Remoteangriff ja Datum 25.03.2026 Stand 26.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Sonstiges
  • Windows

Produktbeschreibung

SolarWinds Platform (ehemals "Orion") ist eine IT Performance-Monitoring Plattform.

Produkte

25.03.2026
- SolarWinds Platform <2026.1.1

Angriff

Angriff

Ein Angreifer kann mehrere Schwachstellen in SolarWinds Platform ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Named provisions

Betroffene Systeme Angriff

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 25th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
WID-SEC-2026-0869

Who this affects

Applies to
Technology companies
Industry sector
5182 Data Processing & Hosting 5112 Software & Technology
Activity scope
Vulnerability Management IT Performance Monitoring
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
IT Security Vulnerability Management

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.