CVE-2024-28988General(solarwinds / web_help_desk)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch solarwinds web_help_desk systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI team was able to discover an unauthenticated attack during their research.  We recommend all Web Help Desk customers apply the patch, which is now available.  We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_help_desk

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
web_help_desk

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-02-25: 1PoC Mentioned / Linked · 2026-01-29: 1Active Exploitation · 2026-01-29: 1Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-25: 101-2801-2902-25
Signal classification3 categories
General
133.3%
Patch
133.3%
Disclosure
133.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-01-281
General1
2026-01-291
Patch1
2026-02-251
Disclosure1
Full discourse3 posts
  • Horizon3.ai@Horizon3ai
    General

    WHD has a history here: CVE-2024-28986 → RCE CVE-2024-28988 → bypass CVE-2025-26399 → bypass Now… CVE-2025-40551 → bypass again

    Post summary

    The post enumerates several CVEs with brief labels (RCE, bypass) and points out a recurring bypass for the latest CVE, but it does not provide actionable exploitation, mitigation, or patch details.

    10000115
    2.6K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    SolarWinds Web Help Desk hit by CVE-2024-28988, a pre-auth deserialization RCE allowing unauthorized access. Disclosed Oct 2024 via ZDI, patch only released Sept 2025. #Vulnerability https://threatcluster.io/cluster/solarwinds-web-help-desk-pre-auth-rce-vulnerability-disclose-594413dc

    Post summary

    SolarWinds Web Help Desk is affected by CVE-2024-28988, a pre‑authentication deserialization RCE disclosed in October 2024 via ZDI, with a patch released in September 2025.

    0000076
    81 followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2024-28988 : CRITICAL RCE ALERT 🚨 @SolarWinds An unauthenticated remote code execution vulnerability has been disclosed in SolarWinds Web Help Desk, a widely deployed IT ticketing platform with privileged access to enterprise systems and sensitive user data. Risk Severity: Critical (CVSS 9.8, active exploitation, trending, public PoC) Impact: Unauthenticated remote code execution as SYSTEM/root Immediate full system compromise Credential extraction from AD, LDAP, and vault integrations Persistent backdoors and ransomware staging Lateral movement toward domain takeover Root Cause: CWE-502 (Deserialization of Untrusted Data). The application deserializes attacker-controlled Java objects from HTTP requests without validation, allowing malicious gadget chains to execute arbitrary commands. Attackers can: Send crafted POST requests to vulnerable REST endpoints Deliver malicious serialized Java payloads Execute arbitrary system commands without credentials Access sensitive help desk data and administrative workflows Pivot deeper into enterprise networks Are You Affected? Vulnerable: Web Help Desk 12.7.0 – 12.8.2 Fixed: 12.8.3 Hotfix 1+ Immediate Action Required: Update: Upgrade to 12.8.3 Hotfix 1+ immediately Mitigation: Restrict access to VPN-only networks and block untrusted inbound traffic Audit: Hunt for anomalous POST requests, Runtime.exec activity, unauthorized admin actions, and unexpected outbound connections Internet-facing instances should be treated as actively targeted. Patch without delay. 🛡️ #solarwinds #security #ostorlabCVE

    Post summary

    CVE‑2024‑28988 is a critical unauthenticated RCE in SolarWinds Web Help Desk, actively exploited in the wild; immediate patching to 12.8.3 Hotfix 1+ and network restrictions are required.

    00000102
    581 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsweb_help_desk---
Appsolarwindsweb_help_desk12.8.3--
Appsolarwindsweb_help_desk12.8.3--
Appsolarwindsweb_help_desk12.8.3--

Explore more