logo

SolarWinds warns of critical Web Help Desk RCE, auth bypass flaws

ID: aaf590b8-5d09-5948-a243-913178861307

STIX ID: report--aaf590b8-5d09-5948-a243-913178861307

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

SolarWinds released Web Help Desk 2026.1 to patch multiple critical vulnerabilities — unauthenticated authentication bypasses (CVE-2025-40552, CVE-2025-40554), deserialization-based remote code execution (CVE-2025-40553, CVE-2025-40551), and a high-severity hardcoded credentials issue (CVE-2025-40537) — and advises immediate patching for the widely used product given prior active exploitation of WHD flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.