logo

CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog

ID: 2e067f74-bae5-5e75-8a67-07120b174ae1

STIX ID: report--2e067f74-bae5-5e75-8a67-07120b174ae1

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-02-04

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA added a critical unauthenticated deserialization vulnerability in SolarWinds Web Help Desk (CVE-2025-40551, CVSS 9.8) to its Known Exploited Vulnerabilities catalog and flagged it as actively exploited; SolarWinds published WHD 2026.1 fixes. The alert also lists other high-severity FreePBX and GitLab CVEs, highlights historical abuse and a weaponized PHP web shell (EncystPHP) used to maintain persistence and abuse telephony resources, and sets remediation deadlines for federal agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.