SolarWinds addressed four critical Web Help Desk flaws
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-40551 | Unauthenticated Deserialization RCE in SolarWinds Web Help Desk SolarWinds Web Help Desk contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to reach the vulnerable functionality over the network and have it deserialize attacker-supplied input. By sending crafted serialized data, the attacker triggers remote code execution and can run arbitrary commands on the host machine running Web Help Desk. Successful compromise grants control of the help desk server, and observed intrusions include attackers installing Zoho agents and Velociraptor for post-exploitation. Any organization running the product is affected, particularly instances exposed to the internet; the flaw carries a CVSS 9.8 (critical) score and federal agencies are under a CISA (BOD 22-01) patching deadline. The vulnerability is being actively exploited in the wild and was added to the CISA KEV catalog on 2026-02-03, with an EPSS probability of 83.6% that it will be exploited within 30 days. Do: Upgrade Web Help Desk to the latest patched release per the SolarWinds security advisory (the source data does not specify a fixed version number), and follow BOD 22-01 mitigations or discontinue use if mitigation is not possible, noting the federal patching deadline. Until patched, restrict internet-facing access to the Web Help Desk server. Check hosts for post-exploitation artifacts reported in the wild, such as unexpected Zoho agent installations and Velociraptor, and review logs for unauthenticated requests targeting the application. | 9.8 group max | 84% | KEV |
| large≈ tens of thousands of on-premises deployments worldwide (order of magnitude: 10,000–100,000 systems), an estimate |
Full article548 words · extracted from securityaffairs.com · click to collapse

SolarWinds patched six Web Help Desk vulnerabilities, including four critical flaws exploitable without authentication for RCE or auth bypass.
SolarWinds released security updates to address six Web Help Desk vulnerabilities, including four critical bugs that allow unauthenticated remote code execution or authentication bypass.
The three critical flaws found by watchTowr, and specifically by researcher Piotr Bazydlo, affect SolarWinds Web Help Desk and can be exploited without authentication, exposing affected systems to severe risk.
The first issue, tracked as CVE-2025-40552, is an authentication bypass vulnerability that allows a remote attacker to circumvent access controls and execute actions and methods that should only be available to authenticated users. Exploitation of this flaw could give an attacker broad control over the application.
The second vulnerability, CVE-2025-40553, is caused by the deserialization of untrusted data and can be exploited to achieve remote code execution. Because authentication is not required, an attacker could run arbitrary commands on the underlying host system, potentially leading to a full system compromise.
The third flaw, CVE-2025-40554, is another authentication bypass vulnerability that enables an attacker to invoke specific internal actions within Web Help Desk without proper authorization. While more targeted in scope, successful exploitation could still allow unauthorized access to sensitive functionality and be used as a stepping stone for further attacks.
The fourth critical flaw, tracked as CVE-2025-40551, was found by Jimi Sebree of Horizon3.ai and affects SolarWinds Web Help Desk through the deserialization of untrusted data. This vulnerability allows an unauthenticated attacker to achieve remote code execution, enabling the execution of arbitrary commands on the underlying host system and potentially leading to a complete compromise of the affected server. Due to its impact and lack of authentication requirements, the issue is rated critical (CVSS 9.8).
“We discovered a handful of security issues in Solarwinds Web Help Desk. These issues include…
- … an unauthenticated remote-code execution vulnerability via deserialization.
- … static credentials that allow limited access to authenticated functionality.
- … a security protection bypass regarding protected site actions.
These vulnerabilities are easily exploitable and enable unauthenticated attackers to achieve remote code execution on vulnerable Solarwinds Web Help Desk instances.” reads the advisory published by Horizon3. “Solarwinds has stated that these issues are patched in Web Help Desk version 2026.1, and we encourage all users to upgrade as soon as possible.“
All the critical flaws have a CVSS score of 9.8.
In addition to this critical issue, Horizon3.ai also identified two high-severity vulnerabilities. The first, CVE-2025-40536, is a security control bypass vulnerability that could allow an unauthenticated attacker to access certain restricted functionality within Web Help Desk. While more limited in scope than the critical flaws, successful exploitation could still expose sensitive features and weaken the application’s overall security posture.
The second high-severity issue, CVE-2025-40537, involves the presence of hardcoded credentials in SolarWinds Web Help Desk. Under specific conditions, this vulnerability could be exploited to gain access to administrative functions, significantly increasing the risk of privilege escalation and unauthorized system management.
Together, these findings underscore systemic weaknesses in authentication, authorization, and secure coding practices within SolarWinds Web Help Desk, particularly when combined with the previously disclosed critical vulnerabilities.
Web Help Desk version 2026.1 fixed all these six vulnerabilities.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, SolarWinds)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187470/security/solarwinds-addressed-four-critical-web-help-desk-flaws.html