CISA orders federal agencies to patch exploited SolarWinds bug by Friday
ID: 6577bb70-ed8b-55a7-98b0-26efe5900f98
STIX ID: report--6577bb70-ed8b-55a7-98b0-26efe5900f98
Feed Name: The Record from Recorded Future News
Threat Score
A critical deserialization vulnerability, CVE-2025-40551 (CVSS 9.8), in SolarWinds Web Help Desk is being actively exploited; CISA added it to the Known Exploited Vulnerabilities catalog and federal civilian agencies have been instructed to patch. Horizon3.ai researchers reported the flaw and SolarWinds released Web Help Desk 2026.1 to fix this and related bypass issues, so affected organizations should apply the update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
