logo

Critical hardcoded SolarWinds credential now exploited in the wild

ID: 54cd2cca-5677-566f-bdd7-2446f0c331d6

STIX ID: report--54cd2cca-5677-566f-bdd7-2446f0c331d6

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-10-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical hardcoded-credential vulnerability (CVE-2024-28987) in SolarWinds Web Help Desk, rated CVSS 9.1 and reported as exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog; SolarWinds released a manual hotfix (12.8.3 HF2) but roughly 827 instances remained internet-exposed as of late September, creating elevated risk of credential abuse and lateral movement—particularly in state/local government and education deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.