RussianPanda 🐼 🇺🇦[verified]@RussianPanda9xxActive Exploitation
A blog post reports that threat actors are actively exploiting CVE-2025-26399 in SolarWinds Web Help Desk, detailing their tradecraft and urging users to upgrade to version 2026.1.
Jamie Levy🦉[verified]@gleedaActive Exploitation
The text advertises a role that involves responding to real‑world attacks, citing CVEs that have been actively exploited in the wild.
John Hammond[verified]@_JohnHammondActive Exploitation
The tweet links to a Huntress Labs article announcing that CVE‑2025‑26399 is actively being exploited in SolarWinds Web Help Desk.
piyokango[verified]@piyokangoActive Exploitation
CISA has confirmed that three listed CVEs are actively exploited and has added them to the KEV catalog, providing basic technical details and links to vendor advisories that likely contain patches.
中島佑允(YusukeNakajima)[verified]@nakajimeeeeActive Exploitation
SolarWinds Web Help Desk CVE‑2025‑26399 has been actively exploited in the wild, with attackers employing a sophisticated chain of tools and techniques; a patch to version 2026.1 and network hardening are recommended.
Patrick Roland[verified]@DeusLogicaPatch
The tweet highlights that SolarWinds Web Help Desk CVE-2025-26399 is an overdue CISA KEV with deserialization-based command execution via AjaxProxy, urging users to apply patches immediately.
Patrick Roland[verified]@DeusLogicaActive Exploitation
The tweet announces that SolarWinds Workflow Health Dashboard is affected by CVE-2025-26399, an RCE vulnerability that has been identified as a known exploited vulnerability (CISA KEV), though it provides no PoC, exploit code, patch, or debunking information.
Patrick Roland[verified]@DeusLogicaDisclosure
The announcement highlights a critical RCE flaw in SolarWinds Workflow Health Dashboard, with no PoC, exploit, or patch details provided. The focus is on informing about the vulnerability’s existence and severity.