logo

CISA warns critical SolarWinds RCE bug is exploited in attacks

ID: 95d995af-ba3d-50ae-a8bd-0a564c8316d7

STIX ID: report--95d995af-ba3d-50ae-a8bd-0a564c8316d7

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-08-16

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA warned that threat actors are exploiting a critical Java deserialization RCE in SolarWinds Web Help Desk (CVE-2024-28986). SolarWinds released a hotfix and guidance, cautioned about SAML SSO compatibility, and recommended backups; CISA added the CVE to its Known Exploited Vulnerabilities catalog and mandated federal patching within three weeks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.