ZeroHour
The Recordpublished ()ingested

CISA orders federal agencies to patch exploited SolarWinds bug by Friday

criticalVulnerability exploited in the wildimportance 60CVE-2025-40551CVE-2024-28986

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-28986
Java Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk is susceptible to a Java deserialization of untrusted data flaw (CWE-502) in which maliciously crafted serialized Java data sent to the application can trigger remote code execution on the host machine. The flaw is rated 9.8 (network vector, no privileges or user interaction required), though SolarWinds has been unable to reproduce exploitation without authentication after thorough testing and recommends patching all deployments out of caution. A successful attacker gains the ability to run arbitrary commands on the Web Help Desk server, typically yielding control of the host and access to help-desk data. All Web Help Desk versions are potentially affected, and SolarWinds has released a hotfix/patch to address the issue. The bug is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-15, ordered federal agencies to patch by a Friday deadline, and EPSS estimates an 84.6% probability of exploitation within 30 days (100th percentile).

Do: Upgrade every Web Help Desk deployment to the patched release per SolarWinds' security advisory (a hotfix addressing the issue in all versions is available); if immediate patching is not possible, restrict network access to the Web Help Desk web interface and watch the host for signs of command execution. Federal agencies must meet the CISA KEV remediation deadline, and defenders should also review SolarWinds' related Web Help Desk advisories (including the separately fixed hardcoded-credential issue) while patching.

9.885% KEV
  • SolarWinds Web Help Desk all versions prior to the vendor hotfix/patch (SolarWinds stated the critical RCE affected all Web Help Desk versions; upgrade to the latest patched release per
moderateplausibly on the order of tens of thousands of on-premises deployments, with internet-exposed instances likely numbering in the low thousands
CVE-2025-40551
Unauthenticated Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to reach the vulnerable functionality over the network and have it deserialize attacker-supplied input. By sending crafted serialized data, the attacker triggers remote code execution and can run arbitrary commands on the host machine running Web Help Desk. Successful compromise grants control of the help desk server, and observed intrusions include attackers installing Zoho agents and Velociraptor for post-exploitation. Any organization running the product is affected, particularly instances exposed to the internet; the flaw carries a CVSS 9.8 (critical) score and federal agencies are under a CISA (BOD 22-01) patching deadline. The vulnerability is being actively exploited in the wild and was added to the CISA KEV catalog on 2026-02-03, with an EPSS probability of 83.6% that it will be exploited within 30 days.

Do: Upgrade Web Help Desk to the latest patched release per the SolarWinds security advisory (the source data does not specify a fixed version number), and follow BOD 22-01 mitigations or discontinue use if mitigation is not possible, noting the federal patching deadline. Until patched, restrict internet-facing access to the Web Help Desk server. Check hosts for post-exploitation artifacts reported in the wild, such as unexpected Zoho agent installations and Velociraptor, and review logs for unauthenticated requests targeting the application.

9.884% KEV
  • SolarWinds Web Help Desk
large≈ tens of thousands of on-premises deployments worldwide (order of magnitude: 10,000–100,000 systems), an estimate
Full article232 words · extracted from therecord.media · click to collapse

A vulnerability affecting a popular IT help desk tool from software company SolarWinds is being exploited by hackers, according to the U.S. cyber defense agency. 

Federal civilian agencies will have until Friday to patch CVE-2025-40551, a critical vulnerability reported by SolarWinds last week. The company said security researchers at Horizon3.ai discovered the vulnerability and reported it to them. 

CVE-2025-40551 carries a critical severity score of 9.8 out of 10 and impacts SolarWinds Web Help Desk (WHD) — an IT service management platform used by many large organizations to handle  ticketing, asset tracking and other tasks. The tool helps companies centralize IT support operations.

Horizon3.ai researcher Jimi Sebree published a blog about the bug that traced the issue back to another vulnerability discovered in 2024. That bug, CVE-2024-28986, was also added to these Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities list at the time. 

According to Sebree, CVE-2025-40551 is the latest in a series of bugs that are centered around bypasses of fixes to CVE-2024-28986. Sebree discovered and reported CVE-2025-40551 to SolarWinds on December 5. 

Solarwinds has published an update in Web Help Desk version 2026.1 that fixes the issues. The company fixed CVE-2025-40551 and several other security bugs that were recently discovered by researchers. 

CISA added CVE-2025-40551 to the Known Exploited Vulnerabilities catalog alongside three other vulnerabilities that federal civilian agencies will need to patch before the end of the month.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-orders-agencies-patch-solarwinds-vuln