logo

CISA flags critical SolarWinds RCE flaw as exploited in attacks

ID: 762f5116-ad47-5e8e-bbc0-8ef65cb800fd

STIX ID: report--762f5116-ad47-5e8e-bbc0-8ef65cb800fd

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-02-03

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA has added CVE-2025-40551 — an untrusted deserialization vulnerability in SolarWinds Web Help Desk enabling unauthenticated remote code execution — to its known-exploited-vulnerabilities catalog and ordered federal agencies to patch within three days; SolarWinds released Web Help Desk 2026.1 to address this and several other remotely exploitable flaws that are being actively exploited in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.