ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

SolarWinds Web Help Desk Vulnerability Actively Exploited

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-40551
+3 in the same advisory: …40553 …40554 …40552
Unauthenticated Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to reach the vulnerable functionality over the network and have it deserialize attacker-supplied input. By sending crafted serialized data, the attacker triggers remote code execution and can run arbitrary commands on the host machine running Web Help Desk. Successful compromise grants control of the help desk server, and observed intrusions include attackers installing Zoho agents and Velociraptor for post-exploitation. Any organization running the product is affected, particularly instances exposed to the internet; the flaw carries a CVSS 9.8 (critical) score and federal agencies are under a CISA (BOD 22-01) patching deadline. The vulnerability is being actively exploited in the wild and was added to the CISA KEV catalog on 2026-02-03, with an EPSS probability of 83.6% that it will be exploited within 30 days.

Do: Upgrade Web Help Desk to the latest patched release per the SolarWinds security advisory (the source data does not specify a fixed version number), and follow BOD 22-01 mitigations or discontinue use if mitigation is not possible, noting the federal patching deadline. Until patched, restrict internet-facing access to the Web Help Desk server. Check hosts for post-exploitation artifacts reported in the wild, such as unexpected Zoho agent installations and Velociraptor, and review logs for unauthenticated requests targeting the application.

9.884% KEV
  • SolarWinds Web Help Desk
large≈ tens of thousands of on-premises deployments worldwide (order of magnitude: 10,000–100,000 systems), an estimate
Full article355 words · extracted from infosecurity-magazine.com · click to collapse

A US security agency has warned SolarWinds Web Help Desk users that a remote code execution (RCE) vulnerability patched by the vendor last week is being actively exploited.

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-40551 to its Known Exploited Vulnerabilities (KEV) Catalog yesterday, giving federal civilian agencies until Friday to patch it.

The CVE has a CVSS score of 9.8 as it could allow unauthenticated adversaries to gain admin-level access to help-desk systems in low complexity attacks.

It’s described by CISA as a “deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine.”

Read more on SolarWinds CVEs: SolarWinds Urges Upgrade After Revealing Critical RCE Bug.

The three-day deadline mandated by CISA hints at the seriousness of potential exploitation. The popular IT ticketing software is used across government, but also in the private sector, especially in education and healthcare.

Although CISA’s KEV applies only to federal agencies, enterprises should broadly follow the same advice in order to minimize their attack surface.

Four Critical Vulnerabilities Identified 

Discovered by Jimi Sebree of Horizon3.ai, CVE-2025-40551 is one of four critical vulnerabilities found in SolarWinds Web Help Desk and fixed by the vendor in an update on January 28.

The remaining three were found by Piotr Bazydlo from watchTowr. CVE-2025-40553 is given the exact same description as CVE-2025-40551: a deserialization of untrusted data RCE vulnerability.

CVE-2025-40552 is an authentication bypass vulnerability which could allow an attacker to “execute actions and methods that should be protected by authentication.” CVE-2025-40554 is also an authentication bypass vulnerability, but one which, if exploited, “could allow an attacker to invoke specific actions within Web Help Desk.”

All four are assigned CVSS scores of 9.8, although only CVE-2025-40551 appears to be under active exploitation at the time of writing.

Attackers could chain CVE-2025-40552 or CVE-2025-40554 with CVE-2025-40551 or CVE-2025-40553 to gain complete control of targeted systems for lateral movement, data theft and ransomware.

Customers are urged to update vulnerable servers to Web Help Desk 2026.1 as soon as possible according to SolarWinds’ instructions.

Image credit: Ascannio / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/solarwinds-web-help-desk/