logo

SolarWinds Web Help Desk Vulnerability Actively Exploited

ID: f7c25f6d-599c-553f-a450-58db571d8b98

STIX ID: report--f7c25f6d-599c-553f-a450-58db571d8b98

Feed Name: Infosecurity Magazine (News)

Threat Score
88/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

...
...

CISA has warned that SolarWinds Web Help Desk contains four critical vulnerabilities (notably CVE-2025-40551, a deserialization RCE) with CVSS scores of 9.8; at least CVE-2025-40551 is being actively exploited, prompting a KEV listing and an urgent patching directive for federal agencies — SolarWinds urges customers to upgrade to Web Help Desk 2026.1 to mitigate risks including admin takeover, lateral movement, data theft and ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.