SolarWinds Web Help Desk Exploitation - February 2026
ID: 48fecbbc-0878-55c7-9453-973361416f4c
STIX ID: report--48fecbbc-0878-55c7-9453-973361416f4c
Feed Name: Elastic Security Labs
On February 6, 2026, Microsoft reported active exploitation of Internet-facing SolarWinds Web Help Desk servers (initial activity from Dec 2025) leveraging one or more disclosed CVEs (CVE-2025-26399, CVE-2025-40536, CVE-2025-40551). Post-exploitation activity included installing remotely hosted MSI RMM agents and legitimate tools (Velociraptor, Cloudflared), disabling Defender, setting up QEMU-based scheduled-task tunnels for persistent SSH access, and credential dumping including extraction of NTDS.dit; the report includes Elastic SIEM/Defend detections, prevention artifacts, and recommendations to patch, rotate credentials, review hosts, and remove unauthorized RMM usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
