ZeroHour
The Recordpublished ()ingested

CISA shortens patch deadline for critical Ivanti, SolarWinds bugs

criticalVulnerability exploited in the wildimportance 60CVE-2025-26399CVE-2026-1603

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-26399
Unauthenticated Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains an unauthenticated deserialization of untrusted data vulnerability (CWE-502) in its AjaxProxy component that allows remote attackers to run arbitrary commands on the host machine without any credentials or user interaction. It is triggered by sending a crafted request to the AjaxProxy endpoint of an affected Web Help Desk installation. Successful exploitation yields full code execution on the server, and the flaw is known to be used in ransomware campaigns. Any organization running SolarWinds Web Help Desk is affected, including installations already patched for the earlier CVE-2024-28988 and CVE-2024-28986, since this flaw is a patch bypass of both. The flaw carries a very high exploitation probability (EPSS ~89.5%) and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09 with known ransomware use.

Do: Immediately apply SolarWinds' hotfix for CVE-2025-26399 per the vendor's instructions — organizations that previously patched CVE-2024-28988 or CVE-2024-28986 must apply the new hotfix because those patches do not close this flaw. If the hotfix cannot be applied right away, restrict network access to Web Help Desk (firewall/VPN, limit exposure of the service to the internet) and discontinue use if mitigations are unavailable, per CISA KEV/BOD 22-01 guidance. Given known ransomware use, review Web Help Desk hosts for signs of compromise, including unexpected process execution and accounts or data accessed via the server.

9.890% KEV ransomware
  • SolarWinds Web Help Desk
moderatelow thousands of internet-exposed Web Help Desk instances, with a total on-prem install base plausibly in the tens of thousands
CVE-2026-1603
Authentication Bypass in Ivanti Endpoint Manager Leaks Stored Credentials

CVE-2026-1603 is an authentication bypass (CWE-288/CWE-306) in Ivanti Endpoint Manager (EPM) that affects versions before 2024 SU5. A remote, unauthenticated attacker can send crafted network requests to a vulnerable EPM core server without valid credentials. Successful exploitation grants read access to specific stored credential data held by EPM, which could be leveraged for further access within the environment. Any organization running an EPM deployment on a version earlier than 2024 SU5 is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09, confirming active exploitation in the wild, and its EPSS score of 80.6% (100th percentile) indicates a very high likelihood of exploitation in the next 30 days; no public proof-of-concept is known, suggesting private exploit use.

Do: Upgrade EPM core servers to version 2024 SU5 (or later) as soon as possible, in line with CISA's KEV and BOD 22-01 timelines, which have been shortened for this flaw. Until patched, restrict internet-facing exposure of EPM services and review EPM servers for anomalous authentication activity or signs of stored-credential access. If mitigations are unavailable, follow CISA's guidance to apply vendor-recommended mitigations or discontinue use of the affected product.

7.581% KEV
  • Ivanti Endpoint Manager (EPM) all versions before 2024 SU5
largetens of thousands of EPM core-server deployments (order of 10,000–100,000 installations), an estimate
Full article364 words · extracted from therecord.media · click to collapse

Federal agencies will have significantly less time than usual to patch three different vulnerabilities following reports that they are being exploited by cybercriminals and nation-state actors. 

The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal civilian agencies until Thursday to patch CVE-2025-26399 — a critical vulnerability impacting the popular SolarWinds Web Help Desk, an IT service management platform used by many government agencies to handle ticketing, asset tracking and other tasks. The tool is used to centralize IT support operations.

The bug was discovered by Trend Micro’s Zero Day Initiative in September and researchers have warned since then that it is being exploited. 

Several cybersecurity experts said the issue can be traced back to a vulnerability discovered in 2024. CVE-2025-26399 is the third fix for that bug. 

“In its third iteration of patching, only time will tell whether or not this flaw is in attackers' crosshairs and will see exploitation,” Scott Caveza, senior staff research engineer at Tenable, said in September. 

This is the third time in the last month that CISA has ordered all federal civilian agencies to immediately patch a vulnerability affecting the SolarWinds Web Help Desk tool. 

In early February, CISA gave federal agencies only four days to patch another vulnerability affecting it. Two weeks later, federal agencies were given a three-day deadline to patch another bug in the software. 

SolarWinds software is used by dozens of federal agencies and was previously targeted by Russian hackers as part of one of the largest nation-state attacks in U.S. history

In addition to CVE-2025-26399, CISA added two other vulnerabilities to its catalog of exploited bugs on Monday — both of which have to be patched by federal agencies within two weeks. Nearly all of the vulnerabilities added to the Known Exploited Vulnerabilities catalog are given a three-week patch deadline and the date has only been shortened in rare circumstances.

One of the bugs — CVE-2026-1603 affecting a product from IT company Ivanti — has allegedly been exploited since the middle of February, according to cybersecurity defenders. A Google report on zero-day vulnerabilities found Chinese nation-state attackers repeatedly targeted Ivanti throughout 2025 with novel bugs used to breach Ivanti tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-shortens-patch-deadline-ivanti-solarwinds