SolarWinds Product Security Update Advisory (CVE-2025-26395)
Overview
SolarWinds has released security updates to fix vulnerabilities in SolarWinds products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-26395
SolarWinds SWOSH Versions: 2025.1.1 and earlier
Resolved Vulnerabilities
Cross-site scripting (XSS) vulnerability due to an unvalidated field in a URL in SolarWinds SWOSH (CVE-2025-26395)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-26395
SolarWinds SWOSH Version: 2025.2
References
[1] SolarWinds SWOSH DOM-based Reflected XSS Vulnerability ( CVE-2025-26395 )
https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26395