ZeroHour
Security Affairspublished ()ingested @securityaffairs

Attackers abuse SolarWinds Web Help Desk to install Zoho agents and Velociraptor

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-40551CVE-2025-26399CVE-2025-40536

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-26399
Unauthenticated Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains an unauthenticated deserialization of untrusted data vulnerability (CWE-502) in its AjaxProxy component that allows remote attackers to run arbitrary commands on the host machine without any credentials or user interaction. It is triggered by sending a crafted request to the AjaxProxy endpoint of an affected Web Help Desk installation. Successful exploitation yields full code execution on the server, and the flaw is known to be used in ransomware campaigns. Any organization running SolarWinds Web Help Desk is affected, including installations already patched for the earlier CVE-2024-28988 and CVE-2024-28986, since this flaw is a patch bypass of both. The flaw carries a very high exploitation probability (EPSS ~89.5%) and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09 with known ransomware use.

Do: Immediately apply SolarWinds' hotfix for CVE-2025-26399 per the vendor's instructions — organizations that previously patched CVE-2024-28988 or CVE-2024-28986 must apply the new hotfix because those patches do not close this flaw. If the hotfix cannot be applied right away, restrict network access to Web Help Desk (firewall/VPN, limit exposure of the service to the internet) and discontinue use if mitigations are unavailable, per CISA KEV/BOD 22-01 guidance. Given known ransomware use, review Web Help Desk hosts for signs of compromise, including unexpected process execution and accounts or data accessed via the server.

9.890% KEV ransomware
  • SolarWinds Web Help Desk
moderatelow thousands of internet-exposed Web Help Desk instances, with a total on-prem install base plausibly in the tens of thousands
CVE-2025-40551
+1 in the same advisory: …40536
Unauthenticated Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to reach the vulnerable functionality over the network and have it deserialize attacker-supplied input. By sending crafted serialized data, the attacker triggers remote code execution and can run arbitrary commands on the host machine running Web Help Desk. Successful compromise grants control of the help desk server, and observed intrusions include attackers installing Zoho agents and Velociraptor for post-exploitation. Any organization running the product is affected, particularly instances exposed to the internet; the flaw carries a CVSS 9.8 (critical) score and federal agencies are under a CISA (BOD 22-01) patching deadline. The vulnerability is being actively exploited in the wild and was added to the CISA KEV catalog on 2026-02-03, with an EPSS probability of 83.6% that it will be exploited within 30 days.

Do: Upgrade Web Help Desk to the latest patched release per the SolarWinds security advisory (the source data does not specify a fixed version number), and follow BOD 22-01 mitigations or discontinue use if mitigation is not possible, noting the federal patching deadline. Until patched, restrict internet-facing access to the Web Help Desk server. Check hosts for post-exploitation artifacts reported in the wild, such as unexpected Zoho agent installations and Velociraptor, and review logs for unauthenticated requests targeting the application.

9.884% KEV
  • SolarWinds Web Help Desk
large≈ tens of thousands of on-premises deployments worldwide (order of magnitude: 10,000–100,000 systems), an estimate

Indicators of compromiseAll →

TypeIndicatorContext
domainproton.meZoho Assist account tied to a Proton Mail address, esmahyft@proton[.]me .” continues the report. “Once the Zoho ManageEngine RMM
Full article547 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 09, 2026

Huntress confirmed active SolarWinds Web Help Desk exploits, where attackers installed Zoho tools for persistence, and used Velociraptor for control.

On February 7, 2026, Huntress investigated an active attack abusing SolarWinds Web Help Desk flaws. Attackers exploited unpatched versions to run code remotely, then quickly installed Zoho ManageEngine tools for persistent remote access and Cloudflare tunnels.

“This intrusion stemmed from the many recently disclosed vulnerabilities affecting SolarWinds WHD. The most critical vulnerabilities grant an adversary arbitrary code execution via untrusted deserialization — CVE-2025-40551 was recently added to CISA’s Known Exploited Vulnerabilities database, and CVE-2025-26399 was just recently discussed by Microsoft and other vendors who have also observed active in-the-wild exploitation.” reads the report published by Huntress. “They used Velociraptor to control systems and ran domain discovery commands to map networks. The activity confirms real-world exploitation of critical SolarWinds WHD vulnerabilities now tracked by CISA.”

Huntress observed active post-exploitation after attackers compromised SolarWinds Web Help Desk. The attack started from the WHD service, which silently installed a Zoho ManageEngine RMM agent to gain persistent remote access.

“Interestingly, the Zoho Assist agent was configured for unattended access, registering the compromised host to a Zoho Assist account tied to a Proton Mail address, esmahyft@proton[.]me.” continues the report. “Once the Zoho ManageEngine RMM agent was established, the threat actor wasted no time pivoting to hands-on-keyboard activity. Using the RMM agent process (TOOLSIQ.EXE) as their operational foothold, they executed Active Directory discovery commands to enumerate domain-joined machines via net group "domain computers" /do, a textbook reconnaissance technique aimed at identifying viable targets for lateral movement.”

Using this foothold, the attacker performed domain reconnaissance, then deployed Velociraptor as a command-and-control tool. Velociraptor was configured to communicate through Cloudflare Workers and included a failover C2 mechanism.

The attacker quickly ran a PowerShell script to collect detailed system information, including OS details, hardware data, domain membership, and installed updates. This data was formatted and sent to an attacker-controlled Elastic Cloud instance hosted on legitimate Google Cloud infrastructure, effectively giving the attacker a centralized dashboard to track and manage compromised systems using Kibana.

To avoid detection, they disabled Windows Defender and the Windows Firewall. They then installed Cloudflared tunnels to maintain hidden remote access and used PowerShell to execute additional commands and manage the system. To ensure long-term persistence, the attacker also created malicious scheduled tasks that abused QEMU to keep access even after reboots.

Below are mitigations provided by the Huntress, along with Indicators of Compromise (IoCs):

  • Update SolarWinds Web Help Desk to version 2026.1 or later, which addresses CVE-2025-26399CVE-2025-40536, and CVE-2025-40551. All prior versions should be considered vulnerable. See the SolarWinds upgrade guide for instructions.
  • WHD administrative interfaces should not be publicly accessible. Place WHD behind a VPN or firewall and remove direct internet access to admin paths.
  • Reset passwords for all service accounts, administrator accounts, and any credentials accessible through or stored within the WHD application.
  • Review WHD hosts for unauthorized remote access tools (Zoho Assist, Velociraptor, Cloudflared, VS Code tunnels), unexpected services, encoded PowerShell execution, and silent MSI installations spawned by the WHD service process (java.exe / wrapper.exe).

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SolarWinds Web Help Desk)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187761/security/attackers-abuse-solarwinds-web-help-desk-to-install-zoho-agents-and-velociraptor.html