SolarWinds Web Help Desk Exploited for RCE in Multi
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-26399 | Unauthenticated Deserialization RCE in SolarWinds Web Help Desk SolarWinds Web Help Desk contains an unauthenticated deserialization of untrusted data vulnerability (CWE-502) in its AjaxProxy component that allows remote attackers to run arbitrary commands on the host machine without any credentials or user interaction. It is triggered by sending a crafted request to the AjaxProxy endpoint of an affected Web Help Desk installation. Successful exploitation yields full code execution on the server, and the flaw is known to be used in ransomware campaigns. Any organization running SolarWinds Web Help Desk is affected, including installations already patched for the earlier CVE-2024-28988 and CVE-2024-28986, since this flaw is a patch bypass of both. The flaw carries a very high exploitation probability (EPSS ~89.5%) and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09 with known ransomware use. Do: Immediately apply SolarWinds' hotfix for CVE-2025-26399 per the vendor's instructions — organizations that previously patched CVE-2024-28988 or CVE-2024-28986 must apply the new hotfix because those patches do not close this flaw. If the hotfix cannot be applied right away, restrict network access to Web Help Desk (firewall/VPN, limit exposure of the service to the internet) and discontinue use if mitigations are unavailable, per CISA KEV/BOD 22-01 guidance. Given known ransomware use, review Web Help Desk hosts for signs of compromise, including unexpected process execution and accounts or data accessed via the server. | 9.8 | 90% | KEV ransomware |
| moderatelow thousands of internet-exposed Web Help Desk instances, with a total on-prem install base plausibly in the tens of thousands | |
| CVE-2025-40551 +1 in the same advisory: …40536 | Unauthenticated Deserialization RCE in SolarWinds Web Help Desk SolarWinds Web Help Desk contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to reach the vulnerable functionality over the network and have it deserialize attacker-supplied input. By sending crafted serialized data, the attacker triggers remote code execution and can run arbitrary commands on the host machine running Web Help Desk. Successful compromise grants control of the help desk server, and observed intrusions include attackers installing Zoho agents and Velociraptor for post-exploitation. Any organization running the product is affected, particularly instances exposed to the internet; the flaw carries a CVSS 9.8 (critical) score and federal agencies are under a CISA (BOD 22-01) patching deadline. The vulnerability is being actively exploited in the wild and was added to the CISA KEV catalog on 2026-02-03, with an EPSS probability of 83.6% that it will be exploited within 30 days. Do: Upgrade Web Help Desk to the latest patched release per the SolarWinds security advisory (the source data does not specify a fixed version number), and follow BOD 22-01 mitigations or discontinue use if mitigation is not possible, noting the federal patching deadline. Until patched, restrict internet-facing access to the Web Help Desk server. Check hosts for post-exploitation artifacts reported in the wild, such as unexpected Zoho agent installations and Velociraptor, and review logs for unauthenticated requests targeting the application. | 9.8 | 84% | KEV |
| large≈ tens of thousands of on-premises deployments worldwide (order of magnitude: 10,000–100,000 systems), an estimate | |
| CVE-2025-6264 | Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. The Admin.Client.UpdateClientConfig is an artifact used to update the client's configuration. This artifact did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions (normally given by the "Investigator" role) to collect it from endpoints and update the configuration. This can lead to arbitrary command execution and endpoint takeover. To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECT_CLIENT given typically by the "Investigator' role). NVD description · AI analysis pending | 5.5 | 1% | PoC ×2 |
| — |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | firstmail.ltd | count with a throwaway email address likely generated using firstmail[.]ltd, a Russia-based disposable mail service. In all, the thre |
| domain | mooo.com | ciraptor agent to connect it to a different server ("v2-api.mooo[.]com") if the original Cloudflare workers[.]dev domain has bee |
| domain | proton.me | Zoho Assist account tied to a Proton Mail address "esmahyft@proton[.]me." Executed Active Directory discovery commands to enumera |
| domain | workers.dev | ent server ("v2-api.mooo[.]com") if the original Cloudflare workers[.]dev domain has been detected. It achieves this by sending a r |
Full article1,364 words · extracted from thehackernews.com · click to collapse
Microsoft has revealed that it observed a multi‑stage intrusion that involved the threat actors exploiting internet‑exposed SolarWinds Web Help Desk (WHD) instances to obtain initial access and move laterally across the organization's network to other high-value assets.
That said, the Microsoft Defender Security Research Team said it's not clear whether the activity weaponized recently disclosed flaws (CVE-2025-40551, CVSS score: 9.8, and CVE-2025-40536, CVSS score: 8.1), or a previously patched vulnerability (CVE-2025-26399, CVSS score: 9.8).
"Since the attacks occurred in December 2025 and on machines vulnerable to both the old and new set of CVEs at the same time, we cannot reliably confirm the exact CVE used to gain an initial foothold," the company said in a report published last week.
While CVE-2025-40536 is a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality, CVE-2025-40551 and CVE-2025-26399 both refer to untrusted data deserialization vulnerabilities that could lead to remote code execution.
Last week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-40551 to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. Federal Civilian Executive Branch (FCEB) agencies were ordered to apply the fixes for the flaw by February 6, 2026.
In the attacks detected by Microsoft, successful exploitation of the exposed SolarWinds WHD instance allowed the attackers to achieve unauthenticated remote code execution and run arbitrary commands within the WHD application context.
"Upon successful exploitation, the compromised service of a WHD instance spawned PowerShell to leverage BITS [Background Intelligent Transfer Service] for payload download and execution," researchers Sagar Patil, Hardik Suri, Eric Hopper, and Kajhon Soyini noted.
In the next stage, the threat actors downloaded legitimate components associated with Zoho ManageEngine, a legitimate remote monitoring and management (RMM) solution, to enable persistent remote control over the infected system. The attackers followed it up with a series of actions -
- Enumerated sensitive domain users and groups, including Domain Admins.
- Established persistence via reverse SSH and RDP access, with the attackers also attempting to create a scheduled task to launch a QEMU virtual machine under the SYSTEM account at system startup to cover up the tracks within a virtualized environment while exposing SSH access via port forwarding.
- Used DLL side-loading on some hosts by using "wab.exe," a legitimate system executable associated with the Windows Address Book, to launch a rogue DLL ("sspicli.dll") to dump the contents of LSASS memory and conduct credential theft.
In at least one case, Microsoft said the threat actors conducted a DCSync attack, where a Domain Controller (DC) is simulated to request password hashes and other sensitive information from an Active Directory (AD) database.
To counter the threat, users are advised to keep the WHD instances up-to-date, find and remove any unauthorized RMM tools, rotate service and admin accounts, and isolate compromised machines to limit the breach.
"This activity reflects a common but high-impact pattern: a single exposed application can provide a path to full domain compromise when vulnerabilities are unpatched or insufficiently monitored," the Windows maker said.
"In this intrusion, attackers relied heavily on living-off-the-land techniques, legitimate administrative tools, and low-noise persistence mechanisms. These tradecraft choices reinforce the importance of defense in depth, timely patching of internet-facing services, and behavior-based detection across identity, endpoint, and network layers."
Update
In a report published on February 8, 2026, cybersecurity company Huntress said it investigated a case of SolarWinds WHD exploitation, in which the threat actor rapidly deployed Zoho Meetings and Cloudflare tunnels for persistence, as well as a legitimate forensics tool called Velociraptor for command-and-control (C2). The incident occurred on February 7, 2026.
The following sequence of post-exploitation actions describes how the attack unfolded -
- Launched "cmd.exe" to install a remote MSI payload associated with Zoho ManageEngine RMM and established remote access by configuring the Zoho Assist agent for unattended access and registering the compromised host to a Zoho Assist account tied to a Proton Mail address "esmahyft@proton[.]me."
- Executed Active Directory discovery commands to enumerate domain-joined machines for reconnaissance.
- Leveraged the Zoho Assist remote session to deploy Velociraptor version 0.73.4, an outdated version with a known privilege escalation vulnerability (CVE-2025-6264).
- Used the Velociraptor agent to execute PowerShell commands to check for the presence of "code.exe," a Visual Studio Code binary with the likely intent of establishing a remote tunnel.
- Installed Cloudflared to establish an additional tunnel-based channel for redundant access to the compromised host.
- Executed a PowerShell script that collects comprehensive system information and transmits it directly to an attacker-controlled Elastic Cloud instance.
- Disabled Windows Defender and Windows Firewall via Registry modifications.
- Executed a script that implements a live C2 failover mechanism for the Velociraptor agent to connect it to a different server ("v2-api.mooo[.]com") if the original Cloudflare workers[.]dev domain has been detected. It achieves this by sending a request to the failover server and checking the HTTP response code. If the status is 406 Not Acceptable, the Velociraptor is reconfigured to talk to the new server.
- Created scheduled tasks that use QEMU to open an SSH backdoor as a persistence mechanism.
"The Velociraptor server URL, https://auth.qgtxtebl.workers[.]dev/, utilizes a Cloudflare Worker from the same Cloudflare account we have seen before across multiple intrusions involving ToolShell exploitation, and Warlock ransomware deployment, identified by the shared per-account identifier component of the subdomain: qgtxtebl," Huntress researchers noted.
When asked if the latest set of attacks could also be the work of the Warlock ransomware crew, given the indicators of compromise, Jamie Levy, director of adversary tactics at Huntress, told The Hacker News in an email that "there are definitely some similarities that show that this recent campaign of attacks is from the same threat actor group."
This includes the "usage of the same tools and tactics post compromise," along with reused infrastructure observed in prior campaigns. "We also saw one customer come on after they had been compromised and ransomed, cementing our suspicions even further," Levy added.
Threat Actor Abuses Elastic Cloud SIEM Free Trial
According to a follow-up analysis published by Huntress on March 6, 2026, the aforementioned attack chain involved the threat actor exfiltrating system information to a free trial instance of Elastic Cloud security information and event management (SIEM) named "systeminfo" under their control by means of a PowerShell script.
"While we have previously seen threat actors leveraging Velociraptor and other DFIR-focused tools for command and control, this was the first time we observed an adversary use Elastic Cloud for exfiltration," the company said. "The attacker prepared their own Elastic Cloud free trial, using legitimate Elastic infrastructure, using it as a repository for stolen data across intrusions. They could then triage their victims and compromised endpoints, literally using SIEM technology."
The Elastic Cloud deployment was created by the threat actor on January 28, 2026, by registering their trial account with a throwaway email address likely generated using firstmail[.]ltd, a Russia-based disposable mail service.
In all, the threat actor is estimated to have spent approximately 249 minutes between January 28 and February 4, 2026, running queries against victim data through the Discover interface of Kibana, an open-source data visualization and exploration tool designed for Elasticsearch. Administrative login sessions to the Elastic Cloud instance originated from the following two IP addresses -
- 154.26.156[.]181
- 51.161.152[.]26
It's worth noting that the IP address 51.161.152[.]26, an exit node associated with the Safing Privacy Network (SPN), was also flagged by Palo Alto Networks Unit 42 in July 2025 in connection with a ToolShell campaign aimed at vulnerable Microsoft SharePoint servers.
The Elastic Cloud instance has been found to contain about 216 unique victim hosts that span a wide range of sectors, including government agencies, higher education institutions, financial services, religious and nonprofit organizations, global manufacturing and automotive companies, IT service providers, retail, and construction.
On top of that, evidence has emerged that the threat actor has been conducting opportunistic attacks against vulnerable Gladinet CentreStack, SmarterTools SmarterMail, and Microsoft SharePoint instances as well, per Lumen Technologies Black Lotus Labs. Elastic has since taken down the instance.
(The story was updated after publication to include a response from Huntress.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/02/solarwinds-web-help-desk-exploited-for.html