← Vulnerability feed

Vulnerability record · CVE-2021-35215 · published 1 September 2021

CVE-2021-35215: SolarWinds Orion Platform insecure deserialization RCE

Solarwinds · Orion Platform

The SolarWinds Orion Platform (version 2020.2.5 per the record) contains an insecure deserialization flaw (CWE-502) that allows remote code execution. Because the platform is a central monitoring and management system, a successful exploit can compromise a high-value host that often holds broad network and credential access.

8.8 CVSS 3.1 High EPSS 70% · top 0.6% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score, v2 6.5
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability and very high EPSS, though exploitation requires authentication and no KEV listing or known exploit code is documented.

What it is

The SolarWinds Orion Platform (version 2020.2.5 per the record) contains an insecure deserialization flaw (CWE-502) that allows remote code execution. Because the platform is a central monitoring and management system, a successful exploit can compromise a high-value host that often holds broad network and credential access.

Impact

An authenticated attacker gains remote code execution on the Orion server, with high confidentiality, integrity and availability impact per the CVSS vector. This can lead to full control of the monitoring host and any credentials or managed systems it touches.

Attack surface

Reachable over the network (AV:N) with low attack complexity and no user interaction; the record states authentication is required, and the vector reflects low privileges (PR:L). No specific endpoint or interface is identified in the supplied data.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.697, 99.3rd percentile), indicating elevated likelihood of attempted exploitation. References include a vendor patch advisory and a ZDI advisory, but no public exploit code is confirmed in the record.

What to do

  • Apply the vendor patch referenced in the SolarWinds security advisory for CVE-2021-35215 (upgrade from Orion Platform 2020.2.5 to the fixed release).
  • Restrict network access to the Orion Platform web interface and management ports to trusted administrative networks only.
  • Enforce least privilege and review accounts with access to Orion, since exploitation requires authentication.
  • Monitor and alert on deserialization-related errors or unexpected child processes spawned by Orion services.
  • If patching is delayed, isolate the Orion server and increase logging around authentication and application activity.

Detection

  • Hunt for unusual child processes (cmd.exe, powershell.exe, wscript.exe) spawned by Orion Platform service processes.
  • Review Orion application and web server logs for deserialization exceptions or anomalous serialized payload patterns.
  • Alert on authentication events to Orion from unusual source IPs or accounts followed by process creation on the host.
  • Monitor for outbound connections from the Orion server to unexpected destinations that could indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35215 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10148SolarWinds Orion API authentication bypass allows remote command executionThe SolarWinds Orion Platform API contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker execute API comman…KEVEPSS 92%analysed9.8CVE-2021-27258Solarwinds orion platform improper access control vulnerabilityThis vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…EPSS 4.0%9.8CVE-2021-25274Solarwinds orion platform deserialization of untrusted data vulnerabilityThe Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…EPSS 36%9.8CVE-2019-9546Solarwinds orion platform uncontrolled search path element vulnerabilitySolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.EPSS 2.8%9.6CVE-2021-35222Solarwinds orion platform cross-site scripting vulnerabilityThis vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Setti…EPSS 2.6%9.0CVE-2020-13169Solarwinds orion platform cross-site scripting vulnerabilityStored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may …EPSS 2.2%8.8CVE-2022-36960Solarwinds orion platform improper input validation vulnerabilitySolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co…EPSS 0.91%8.8CVE-2022-36964Solarwinds orion platform deserialization of untrusted data vulnerabilitySolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2021-35215), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.