ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

SolarWinds fixes critical Web Help Desk RCE vulnerability (CVE-2025-26399)

criticalVulnerability exploited in the wildimportance 60CVE-2025-26399CVE-2024-28988CVE-2024-28986

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-28986
Java Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk is susceptible to a Java deserialization of untrusted data flaw (CWE-502) in which maliciously crafted serialized Java data sent to the application can trigger remote code execution on the host machine. The flaw is rated 9.8 (network vector, no privileges or user interaction required), though SolarWinds has been unable to reproduce exploitation without authentication after thorough testing and recommends patching all deployments out of caution. A successful attacker gains the ability to run arbitrary commands on the Web Help Desk server, typically yielding control of the host and access to help-desk data. All Web Help Desk versions are potentially affected, and SolarWinds has released a hotfix/patch to address the issue. The bug is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-15, ordered federal agencies to patch by a Friday deadline, and EPSS estimates an 84.6% probability of exploitation within 30 days (100th percentile).

Do: Upgrade every Web Help Desk deployment to the patched release per SolarWinds' security advisory (a hotfix addressing the issue in all versions is available); if immediate patching is not possible, restrict network access to the Web Help Desk web interface and watch the host for signs of command execution. Federal agencies must meet the CISA KEV remediation deadline, and defenders should also review SolarWinds' related Web Help Desk advisories (including the separately fixed hardcoded-credential issue) while patching.

9.885% KEV
  • SolarWinds Web Help Desk all versions prior to the vendor hotfix/patch (SolarWinds stated the critical RCE affected all Web Help Desk versions; upgrade to the latest patched release per
moderateplausibly on the order of tens of thousands of on-premises deployments, with internet-exposed instances likely numbering in the low thousands
CVE-2024-28988
Unauthenticated Java Deserialization RCE in SolarWinds Web Help Desk

CVE-2024-28988 is a Java deserialization remote code execution flaw (CWE-502) in SolarWinds Web Help Desk that allows an attacker to run commands on the host machine running the application. It is triggered over the network by sending the application crafted input that is deserialized without adequate validation, and requires no authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N). Successful exploitation gives remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8, critical). All Web Help Desk deployments running versions prior to the vendor's hotfix are affected; the flaw was discovered by the Trend Micro Zero Day Initiative (ZDI) team, which found it exploitable without authentication while researching a previously reported Web Help Desk vulnerability. As of this analysis there is no confirmed in-the-wild exploitation, no CISA KEV listing, and no known public PoC, but EPSS assigns a ~39.4% probability of exploitation within 30 days (99th percentile), so defenders should treat it as a high-priority patch.

Do: Apply the hotfix SolarWinds has released for Web Help Desk immediately, per the vendor's advisory, since all customers are urged to patch. If patching is delayed, restrict network access to the Web Help Desk server — especially remove direct internet exposure — and monitor for unexpected command or child-process activity from the Web Help Desk service. Also inventory which of your instances are internet-facing and review their access logs for unauthenticated, suspicious requests.

9.839%
  • SolarWinds Web Help Desk
moderate≈1,000–10,000 internet-exposed Web Help Desk instances (public internet-wide scans); total on-prem install base likely in the low tens of thousands
CVE-2025-26399
Unauthenticated Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains an unauthenticated deserialization of untrusted data vulnerability (CWE-502) in its AjaxProxy component that allows remote attackers to run arbitrary commands on the host machine without any credentials or user interaction. It is triggered by sending a crafted request to the AjaxProxy endpoint of an affected Web Help Desk installation. Successful exploitation yields full code execution on the server, and the flaw is known to be used in ransomware campaigns. Any organization running SolarWinds Web Help Desk is affected, including installations already patched for the earlier CVE-2024-28988 and CVE-2024-28986, since this flaw is a patch bypass of both. The flaw carries a very high exploitation probability (EPSS ~89.5%) and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09 with known ransomware use.

Do: Immediately apply SolarWinds' hotfix for CVE-2025-26399 per the vendor's instructions — organizations that previously patched CVE-2024-28988 or CVE-2024-28986 must apply the new hotfix because those patches do not close this flaw. If the hotfix cannot be applied right away, restrict network access to Web Help Desk (firewall/VPN, limit exposure of the service to the internet) and discontinue use if mitigations are unavailable, per CISA KEV/BOD 22-01 guidance. Given known ransomware use, review Web Help Desk hosts for signs of compromise, including unexpected process execution and accounts or data accessed via the server.

9.890% KEV ransomware
  • SolarWinds Web Help Desk
moderatelow thousands of internet-exposed Web Help Desk instances, with a total on-prem install base plausibly in the tens of thousands
Full article242 words · extracted from helpnetsecurity.com · click to collapse

SolarWinds has fixed yet another unauthenticated remote code execution vulnerability (CVE-2025-26399) in Web Help Desk (WHD), its popular web-based IT ticketing and asset management solution.

SolarWinds WHD CVE-2025-26399

While the vulnerability is currently not being leveraged by attackers, they might soon reverse-engineer the hotfix and create a working exploit. As watchTowr researchers noted, “given SolarWinds’ past, in-the-wild exploitation is highly likely.”

About CVE-2025-26399

“[CVE-2025-26399] exists within the AjaxProxy class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data,” Trend Micro’s Zero Day Initiative explained.

The vulnerability can be exploited without prior authentication. Successful exploitation allows remote attackers to execute arbitrary code on vulnerable SolarWinds WHD installations.

Due to the solution’s nature, a compromised WHD instance could reveal a lot of sensitive information.

CVE-2025-26399 affects SolarWinds WHD version 12.8.7 and is (hopefully fully) addressed in 12.8.7 Hotfix 1.

The urgency to apply the fix comes from the fact that CVE-2025-26399 is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986, which ended up being exploited by attackers soon after the release of a fix.

The good news is that here’s currently no public proof-of-concept exploit available for CVE-2025-26399.

UPDATE (March 9, 2026, 01:25 p.m. ET):

CVE-2025-26399 has been added to CISA’s Known Exploited Vulnerabilities catalog.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/09/24/solarwinds-web-help-desk-rce-cve-2025-26399/