logo

170+ SolarWinds Help Desk Installations Vulnerable to RCE Attacks Exposed Online

ID: 2f43ba70-a0fe-561b-ae93-46071aff11f8

STIX ID: report--2f43ba70-a0fe-561b-ae93-46071aff11f8

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Guru Baran

...
...

SolarWinds Web Help Desk versions prior to 2026.1 contain a critical unauthenticated deserialization RCE (CVE-2025-40551, CVSS 9.8) that has been actively exploited and was added to CISA’s KEV; SolarWinds released 2026.1 to address this and related issues, but Shadowserver identified ~170 publicly exposed vulnerable instances — organizations should apply vendor updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.