logo

SolarWinds Web Help Desk Exploitation - February 2026

ID: 48fecbbc-0878-55c7-9453-973361416f4c

STIX ID: report--48fecbbc-0878-55c7-9453-973361416f4c

Feed Name: Elastic Security Labs

Threat Score
78/100

Date Published: 2026-02-10

Date Updated: 2026-04-27

...
...

On February 6, 2026, Microsoft reported active exploitation of Internet-facing SolarWinds Web Help Desk servers (initial activity from Dec 2025) leveraging one or more disclosed CVEs (CVE-2025-26399, CVE-2025-40536, CVE-2025-40551). Post-exploitation activity included installing remotely hosted MSI RMM agents and legitimate tools (Velociraptor, Cloudflared), disabling Defender, setting up QEMU-based scheduled-task tunnels for persistent SSH access, and credential dumping including extraction of NTDS.dit; the report includes Elastic SIEM/Defend detections, prevention artifacts, and recommendations to patch, rotate credentials, review hosts, and remove unauthorized RMM usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.