logo

A Vulnerability in SolarWinds Web Help Desk Could Allow for Remote Code Execution

ID: 3e0a61de-d304-530f-b9e2-d08ff97810a4

STIX ID: report--3e0a61de-d304-530f-b9e2-d08ff97810a4

Feed Name: CISecurity.org Advisories

Threat Score
80/100

Date Published: 2025-09-23

Date Updated: 2026-04-27

...
...

**Executive summary:** A critical unauthenticated deserialization vulnerability (CVE-2025-26399) in SolarWinds Web Help Desk allows remote code execution as SYSTEM by bypassing previous patches (CVE-2024-28988 and CVE-2024-28986). Exploitation could let attackers run commands, install software, view/change/delete data, or create privileged accounts; the report contains no indication of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.