Vulnerability record · CVE-2021-35216 · published 1 September 2021
CVE-2021-35216: SolarWinds Patch Manager deserialization flaw allows remote code execution
Solarwinds · Patch Manager
The Patch Manager Orion Platform Integration module deserializes untrusted data, allowing an authenticated attacker with network access to run code on the host. Because the flaw is reachable over HTTP and needs only low privileges, it is a serious post-authentication escalation path in a widely deployed management product.
Description
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low-privilege network reach and remote code execution impact, plus a very high EPSS score, make this a high-priority patch despite no KEV listing.
What it is
The Patch Manager Orion Platform Integration module deserializes untrusted data, allowing an authenticated attacker with network access to run code on the host. Because the flaw is reachable over HTTP and needs only low privileges, it is a serious post-authentication escalation path in a widely deployed management product.
Impact
An attacker who holds a valid low-privileged account can execute arbitrary code with the privileges of the Patch Manager service, giving full control of the affected server and its integration with the Orion platform.
Attack surface
Reached over the network via HTTP against the Patch Manager Orion Platform Integration module. Authentication is required (PR:L) and no user interaction is needed (UI:N).
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.814 (99.6th percentile), indicating strong likelihood of exploitation activity. Vendor and ZDI references confirm a patch exists.
What to do
- Apply the SolarWinds Patch Manager 2020.2.6 update or later per the vendor advisory and release notes.
- Restrict network access to the Patch Manager and Orion integration endpoints to trusted management networks only.
- Audit and minimize accounts with access to Patch Manager; remove or disable unused low-privileged accounts.
- Monitor the integration module for unexpected outbound connections or child processes spawned by the service.
- If patching cannot be done immediately, isolate the Patch Manager server from untrusted networks.
Detection
- Alert on unusual child processes or command shells spawned by the Patch Manager or Orion integration service.
- Monitor HTTP requests to Patch Manager integration endpoints for serialized payload patterns or anomalous content types.
- Review authentication logs for low-privileged accounts accessing integration endpoints outside normal administrative workflows.
- Baseline and watch for new outbound network connections from the Patch Manager host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://documentation.solarwinds.com/en/success_center/patchman/content/release_notes/patchman_2020-2-6_release_notes.ht | Release NotesVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35216 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1246/ | Third Party AdvisoryVDB Entry |
| https://documentation.solarwinds.com/en/success_center/patchman/content/release_notes/patchman_2020-2-6_release_notes.ht | Release NotesVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35216 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1246/ | Third Party AdvisoryVDB Entry |
Track CVE-2021-35216 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35216), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.