logo

CISA orders federal agencies to patch exploited SolarWinds bug by Friday

ID: 6577bb70-ed8b-55a7-98b0-26efe5900f98

STIX ID: report--6577bb70-ed8b-55a7-98b0-26efe5900f98

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2026-02-03

Date Updated: 2026-05-01

...
...

A critical deserialization vulnerability, CVE-2025-40551 (CVSS 9.8), in SolarWinds Web Help Desk is being actively exploited; CISA added it to the Known Exploited Vulnerabilities catalog and federal civilian agencies have been instructed to patch. Horizon3.ai researchers reported the flaw and SolarWinds released Web Help Desk 2026.1 to fix this and related bypass issues, so affected organizations should apply the update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.