Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2021-35247
SolarWinds Serv-U — Improper Input Validation Vulnerability in Serv-U
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N R U N L N 4.3 .0345 88.7 YES
AFFECTED
Product Versions Fixed
Serv-U 15.2.5 and previous versions – —
TIMELINE
Jun 22 Reserved by SolarWinds
Jan 7 Published (CNA: SolarWinds)
Jan 21 Added to CISA KEV, remediation due 2022-02-04
Description
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| June 22, 2021 | Reserved | Reserved by SolarWinds |
| January 7, 2022 | Published | Published (CNA: SolarWinds) |
| January 21, 2022 | KEV ADDED | Added to CISA KEV, remediation due 2022-02-04 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| SolarWinds | Serv-U | — | 15.2.5 and previous versions | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-35247 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.