logo

Active Exploitation of SolarWinds Web Help Desk (CVE-2025-26399)

ID: 8fa0f1b1-2b29-55d9-8890-42298cf326d1

STIX ID: report--8fa0f1b1-2b29-55d9-8890-42298cf326d1

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2026-02-08

Date Updated: 2026-04-28

...
...

Huntress observed active exploitation of SolarWinds Web Help Desk vulnerabilities leading to rapid post-exploitation actions across multiple customers: attackers achieved RCE via WHD, silently installed remote MSI payloads (Zoho/ManageEngine RMM, Velociraptor), established redundant C2 (Cloudflared, Cloudflare Workers), disabled Windows security controls, implemented QEMU-based SSH persistence, and exfiltrated system information to an attacker-controlled Elastic Cloud instance; the report provides IOCs, detection guidance, and recommended WHD updates and access restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.