CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-19006 | Authentication Bypass in Sangoma FreePBX Admin Interface Sangoma FreePBX contains an improper authentication flaw (CWE-287) that potentially allows unauthorized users to bypass password authentication on services provided by the FreePBX admin. An attacker triggers it by sending requests to the FreePBX admin interface without valid credentials, defeating the password check rather than exploiting a code-level bug. Successful exploitation grants unauthorized access to FreePBX administrative services, which can expose PBX configuration and allow management actions under another user's privileges. Any Sangoma FreePBX deployment is affected (CISA lists the affected product as Sangoma FreePBX with no version ranges specified), with risk concentrated on systems whose admin interface is reachable from the internet or untrusted networks. The flaw was added to CISA KEV on 2026-02-03, confirming known in-the-wild exploitation; EPSS estimates a 36.6% chance of exploitation within 30 days (98th percentile), and no public proof-of-concept is known. Do: Apply mitigations per vendor instructions as required by CISA KEV, or discontinue use if mitigations are unavailable; federal agencies must follow BOD 22-01 guidance, including for cloud services. Because the flaw bypasses admin authentication, restrict the FreePBX admin interface to trusted networks (VPN or firewall allowlists) and avoid exposing it directly to the internet. Review FreePBX admin access logs for unexpected successful logins or unexplained configuration changes from unknown sources. | 9.8 | 37% | KEV PoC |
| largetens of thousands of internet-exposed FreePBX admin panels (estimate) | |
| CVE-2021-39935 | Server-Side Request Forgery in GitLab Community and Enterprise Editions via CI Lint API CVE-2021-39935 is a server-side request forgery (CWE-918) in GitLab Community Edition and Enterprise Edition that allows unauthorized external users to make the GitLab server issue requests through the CI Lint API. By abusing the server's network position, an attacker can reach internal-only resources such as loopback or private-network services, potentially mapping or accessing internal infrastructure without credentials. All deployments of the affected editions are potentially exposed, with actual risk depending on whether the CI Lint API is reachable by unauthenticated external users. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-03, indicating known exploitation in the wild, though no public proof-of-concept is known and ransomware use is unconfirmed. EPSS estimates a 35.6% probability of exploitation within 30 days (98th percentile). Do: Upgrade GitLab CE/EE to the patched release identified in GitLab's security advisory for CVE-2021-39935 (version numbers are not provided in the source data). Until patching is complete, restrict unauthenticated external access to the CI Lint API (e.g., at the reverse proxy or firewall) and review logs for unexpected requests to loopback or internal-network targets originating from CI lint calls. Federal agencies must follow BOD 22-01 remediation timelines following the 2026-02-03 KEV listing; discontinue or isolate use if mitigations are unavailable. | 7.5 | 36% | KEV |
| largetens of thousands of internet-exposed self-managed GitLab instances; the affected code also runs on GitLab.com SaaS (millions of users) | |
| CVE-2021-45461 | FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. The fixed versions are 15.0.20 and 16.0.19. NVD description · AI analysis pending | 9.8 | 22% | PoC |
| — | |
| CVE-2025-40551 | Unauthenticated Deserialization RCE in SolarWinds Web Help Desk SolarWinds Web Help Desk contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to reach the vulnerable functionality over the network and have it deserialize attacker-supplied input. By sending crafted serialized data, the attacker triggers remote code execution and can run arbitrary commands on the host machine running Web Help Desk. Successful compromise grants control of the help desk server, and observed intrusions include attackers installing Zoho agents and Velociraptor for post-exploitation. Any organization running the product is affected, particularly instances exposed to the internet; the flaw carries a CVSS 9.8 (critical) score and federal agencies are under a CISA (BOD 22-01) patching deadline. The vulnerability is being actively exploited in the wild and was added to the CISA KEV catalog on 2026-02-03, with an EPSS probability of 83.6% that it will be exploited within 30 days. Do: Upgrade Web Help Desk to the latest patched release per the SolarWinds security advisory (the source data does not specify a fixed version number), and follow BOD 22-01 mitigations or discontinue use if mitigation is not possible, noting the federal patching deadline. Until patched, restrict internet-facing access to the Web Help Desk server. Check hosts for post-exploitation artifacts reported in the wild, such as unexpected Zoho agent installations and Velociraptor, and review logs for unauthenticated requests targeting the application. | 9.8 group max | 84% | KEV |
| large≈ tens of thousands of on-premises deployments worldwide (order of magnitude: 10,000–100,000 systems), an estimate | |
| CVE-2025-64328 | Post-Authentication OS Command Injection in Sangoma FreePBX Filestore Module Sangoma FreePBX's filestore module within the Administrative interface (described alongside the Endpoint Manager module) contains an OS command injection flaw (CWE-78) in its testconnection -> check_ssh_connect() function, affecting versions 17.0.2.36 and above before 17.0.3. An attacker who is already authenticated — CVSS 4.0 scoring indicates high privileges are required — can trigger the test-connection function to inject and execute arbitrary operating-system commands. Successful exploitation gives the attacker remote access to the system as the 'asterisk' user, and in observed attacks this has been leveraged to deploy a weaponized web shell. Any FreePBX deployment running the affected module versions is exposed; CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-02-03, and public reporting ties it to web shell campaigns that have compromised 900+ FreePBX instances. EPSS currently assigns an 84.6% probability of exploitation within 30 days (100th percentile), underscoring the urgency of patching. Do: Upgrade the filestore/Endpoint Manager module to version 17.0.3 or later via FreePBX module administration, following vendor instructions — CISA KEV/BOD 22-01 requires applying vendor mitigations or discontinuing use if mitigation is unavailable. Hunt for the weaponized web shell described in Fortinet's referenced research, unexpected files or processes running as the asterisk user, and suspicious activity through the Administrative interface, and restrict admin access to trusted users and networks until patched. | 8.6 | 85% | KEV PoC |
| moderate≥900 confirmed-compromised FreePBX instances; broader internet-exposed installed base unknown |
Full article655 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananFeb 04, 2026Software Security / Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting SolarWinds Web Help Desk (WHD) to its Known Exploited Vulnerabilities (KEV) catalog, flagging it as actively exploited in attacks.
The vulnerability, tracked as CVE-2025-40551 (CVSS score: 9.8), is a untrusted data deserialization vulnerability that could pave the way for remote code execution.
"SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine," CISA said. "This could be exploited without authentication."
SolarWinds issued fixes for the flaw last week, along with CVE-2025-40536 (CVSS score: 8.1), CVE-2025-40537 (CVSS score: 7.5), CVE-2025-40552 (CVSS score: 9.8), CVE-2025-40553 (CVSS score: 9.8), and CVE-2025-40554 (CVSS score: 9.8), in WHD version 2026.1.
There are currently no public reports about how the vulnerability is being weaponized in attacks, who may be the targets, or the scale of such efforts. It's the latest illustration of how quickly threat actors are moving to exploit newly disclosed flaws.
Also added to the KEV catalog are three other vulnerabilities -
- CVE-2019-19006 (CVSS score: 9.8) - An improper authentication vulnerability in Sangoma FreePBX that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX administrator
- CVE-2025-64328 (CVSS score: 8.6) - An operating system command injection vulnerability in Sangoma FreePBX that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function and potentially obtain remote access to the system as an asterisk user
- CVE-2021-39935 (CVSS score: 7.5/6.8) - A server-side request forgery (SSRF) vulnerability in GitLab Community and Enterprise Editions that could allow unauthorized external users to perform Server Side Requests via the CI Lint API
It's worth noting that the exploitation of CVE-2021-39935 was highlighted by GreyNoise in March 2025, as part of a coordinated surge in the abuse of SSRF vulnerabilities in multiple platforms, including DotNetNuke, Zimbra Collaboration Suite, Broadcom VMware vCenter, ColumbiaSoft DocumentLocator, BerriAI LiteLLM, and Ivanti Connect Secure.
By contrast, the abuse of CVE-2019-19006 dates back to November 2020, when Check Point disclosed details of a cyber fraud operation codenamed INJ3CTOR3 that leveraged the flaw to compromise VoIP servers and sell the access to the highest bidders. As recently as last week, Fortinet revealed the threat actor behind the activity has weaponized CVE-2025-64328 starting early December 2025 to deliver a web shell codenamed EncystPHP.
"In 2022, the threat actor shifted its focus to the Elastix system via CVE-2021-45461," security researcher Vincent Li said. "These incidents begin with the exploitation of a FreePBX vulnerability, followed by the deployment of a PHP web shell in the target environments."
Once launched, EncystPHP attempts to collect FreePBX database configuration, sets up persistence by creating a root-level user named newfpbx, resets multiple user account passwords, and modifies the SSH "authorized_keys" file to ensure remote access. The web shell also exposes an interactive interface that supports several predefined operational commands.
This includes file system enumeration, process inspection, querying active Asterisk channels, listing Asterisk SIP peers, and retrieving multiple FreePBX and Elastix configuration files.
"By leveraging Elastix and FreePBX administrative contexts, the web shell operates with elevated privileges, enabling arbitrary command execution on the compromised host and initiating outbound call activity through the PBX environment," Li explained.
"Because it can blend into legitimate FreePBX and Elastix components, such activity may evade immediate detection, leaving affected systems exposed to well-known risks, including long-term persistence, unauthorized administrative access, and abuse of telephony resources."
Federal Civilian Executive Branch (FCEB) agencies are required to fix CVE-2025-40551 by February 6, 2026, and the rest by February 24, 2026, pursuant to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/02/cisa-adds-actively-exploited-solarwinds.html