Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch solarwinds web_help_desk systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI team was able to discover an unauthenticated attack during their research.
We recommend all Web Help Desk customers apply the patch, which is now available.
We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.
WHD has a history here:
CVE-2024-28986 → RCE
CVE-2024-28988 → bypass
CVE-2025-26399 → bypass
Now… CVE-2025-40551 → bypass again
Post summary
The post enumerates several CVEs with brief labels (RCE, bypass) and points out a recurring bypass for the latest CVE, but it does not provide actionable exploitation, mitigation, or patch details.
SolarWinds Web Help Desk hit by CVE-2024-28988, a pre-auth deserialization RCE allowing unauthorized access. Disclosed Oct 2024 via ZDI, patch only released Sept 2025. #Vulnerability
https://threatcluster.io/cluster/solarwinds-web-help-desk-pre-auth-rce-vulnerability-disclose-594413dc
Post summary
SolarWinds Web Help Desk is affected by CVE-2024-28988, a pre‑authentication deserialization RCE disclosed in October 2024 via ZDI, with a patch released in September 2025.
🚨 CVE-2024-28988 : CRITICAL RCE ALERT 🚨 @SolarWinds
An unauthenticated remote code execution vulnerability has been disclosed in SolarWinds Web Help Desk, a widely deployed IT ticketing platform with privileged access to enterprise systems and sensitive user data.
Risk Severity:
Critical (CVSS 9.8, active exploitation, trending, public PoC)
Impact:
Unauthenticated remote code execution as SYSTEM/root
Immediate full system compromise
Credential extraction from AD, LDAP, and vault integrations
Persistent backdoors and ransomware staging
Lateral movement toward domain takeover
Root Cause:
CWE-502 (Deserialization of Untrusted Data).
The application deserializes attacker-controlled Java objects from HTTP requests without validation, allowing malicious gadget chains to execute arbitrary commands.
Attackers can:
Send crafted POST requests to vulnerable REST endpoints
Deliver malicious serialized Java payloads
Execute arbitrary system commands without credentials
Access sensitive help desk data and administrative workflows
Pivot deeper into enterprise networks
Are You Affected?
Vulnerable: Web Help Desk 12.7.0 – 12.8.2
Fixed: 12.8.3 Hotfix 1+
Immediate Action Required:
Update: Upgrade to 12.8.3 Hotfix 1+ immediately
Mitigation: Restrict access to VPN-only networks and block untrusted inbound traffic
Audit: Hunt for anomalous POST requests, Runtime.exec activity, unauthorized admin actions, and unexpected outbound connections
Internet-facing instances should be treated as actively targeted. Patch without delay. 🛡️
#solarwinds#security#ostorlabCVE
Post summary
CVE‑2024‑28988 is a critical unauthenticated RCE in SolarWinds Web Help Desk, actively exploited in the wild; immediate patching to 12.8.3 Hotfix 1+ and network restrictions are required.