ZeroHour

CVE-2025-40536

KEVmoderate

Unauthenticated Security Control Bypass in SolarWinds Web Help Desk

CISA: SolarWinds Web Help Desk Security Control Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
82%p100
Published
()
KEV added
AI analysis

SolarWinds Web Help Desk contains a security control bypass (CWE-693) that lets an unauthenticated, remote attacker reach functionality that should be restricted. The flaw is exploitable over the network without credentials or user interaction, which is why it carries a critical 9.8 CVSS 3.1 score. An attacker gains access to restricted features, and reporting indicates the bug has been exploited alongside related Web Help Desk flaws for unauthenticated remote code execution, with attackers installing remote-access tools such as Zoho agents and Velociraptor. Any organization running SolarWinds Web Help Desk is affected, with internet-facing help desk servers at greatest risk. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2026-02-12, confirming active in-the-wild exploitation, and EPSS assigns it an 81.6% probability of exploitation within 30 days (100th percentile).

What to do: Upgrade SolarWinds Web Help Desk to the latest vendor release, which also addresses related unauthenticated RCE and authentication-bypass flaws; no fixed version number is given in this data, so follow SolarWinds' advisory for the patched release. Because the bug is under active attack, prioritize patching internet-exposed instances, restrict network access to the help desk console, and hunt for signs of compromise such as unexpected Velociraptor deployments or Zoho remote agents. Federal agencies must apply mitigations per vendor instructions and BOD 22-01 guidance within the required timeframe, or discontinue use of the product if mitigations are unavailable.

Affected
SolarWinds Web Help Desk
Estimated exposure
moderate≈2,000–5,000 internet-exposed instances; likely tens of thousands of total deployments (estimate) — Public internet scans of SolarWinds Web Help Desk services typically reveal only a few thousand exposed instances, while the product's popularity among mid-market organizations and MSPs suggests total (largely internal) deployments in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

CISA Known Exploited Vulnerability
Affected
SolarWinds Web Help Desk
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
solarwinds
Products
web help desk
Weakness
CWE-693
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news