CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog
ID: 2e067f74-bae5-5e75-8a67-07120b174ae1
STIX ID: report--2e067f74-bae5-5e75-8a67-07120b174ae1
Feed Name: The Hacker News
CISA added a critical unauthenticated deserialization vulnerability in SolarWinds Web Help Desk (CVE-2025-40551, CVSS 9.8) to its Known Exploited Vulnerabilities catalog and flagged it as actively exploited; SolarWinds published WHD 2026.1 fixes. The alert also lists other high-severity FreePBX and GitLab CVEs, highlights historical abuse and a weaponized PHP web shell (EncystPHP) used to maintain persistence and abuse telephony resources, and sets remediation deadlines for federal agencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
