logo

SolarWinds fixes critical RCE bug affecting all Web Help Desk versions

ID: bfb6b875-766e-5536-b3ee-d4ea58c5347e

STIX ID: report--bfb6b875-766e-5536-b3ee-d4ea58c5347e

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-08-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical Java deserialization vulnerability (CVE-2024-28986) affecting SolarWinds Web Help Desk could permit remote code execution; SolarWinds has released a hotfix (WHD-12.8.3-HF1) and recommends customers upgrade to 12.8.3 and apply the patch. The vendor reports the flaw was reported as potentially exploitable without authentication but could only be reproduced after authentication during their testing, and there is no public evidence of active exploitation at the time of the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.