Apache Solr
Apache · current 10.0.0
The current version of Apache Solr is 10.0.0 (as of 03/03/2026). patchletter checks the official source daily and emails you every new release.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
- CVE-2019-17558Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability
7.5 high · over the network, with a basic account · CISA deadline was 3 May 22
- CVE-2019-0193Apache Solr DataImportHandler Code Injection Vulnerability
7.2 high · over the network, with admin rights only · CISA deadline was 10 Jun 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Apache log4j: Schwachstelle ermöglicht Codeausführung
WID-SEC-W-2022-0351 · 8 Jul
- Apache Solr: Schwachstelle ermöglicht Erlangen von Administratorrechten
WID-SEC-W-2026-1740 · 1 Jun
Apache Solr at a glance
Apache Solr is a widely used open-source search platform built on Lucene, powering search for many applications and sites. Solr ships regular releases plus coordinated security fixes; as a search service that has been the subject of serious remote vulnerabilities, hardening and timely patching are essential.
For admins the security posture is the priority: Solr has had critical, actively exploited vulnerabilities (including remote code execution), so never expose it to the internet unprotected — keep it strictly on the internal network behind access controls, and apply security releases promptly. Updates within a major line are usually manageable; major upgrades can bring index-format and configuration changes — read the notes, back up (or reindex), and test. In SolrCloud, coordinate with ZooKeeper and roll nodes carefully. After updating, verify that indexing and queries work. Track the version and its support window; patchletter surfaces new Solr releases so security fixes aren't missed.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 10 | 10.0.0 | supported |
| 9 | 9.10.1 | supported |
| 8 | 8.11.4 | End of Life |
| 7 | 7.7.3 | End of Life |
| 6 | 6.6.6 | End of Life |
| 5 | 5.5.5 | End of Life |
| 4 | 4.10.4 | End of Life |
| 3 | 3.6.2 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 10.0.0 | STABLE | 03/03/2026 | – |
Frequently asked questions
- What is the latest version of Apache Solr?
- Apache Solr 10.0.0, released 03/03/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Apache Solr release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Apache Solr updates?
- Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.
Never miss a Apache Solr update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch Apache SolrEmbed this badge
Shows the current Apache Solr version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/solr)https://patchletter.com/badge/solr.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).