CVE-2025-26399Active Exploitation(solarwinds / web_help_desk)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch solarwinds web_help_desk systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-12. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_help_desk

Threat summary

  • Active exploitation appears in 51 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 76 mentions across 24 observed days

What's happening

  • Active exploitation reported across 51 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 38 signals
  • Disclosure: 13 classified signals
  • General: 8 classified signals
  • Peaked 14d ago at 14 mentions (2026-03-10); latest day: 1
  • 76 total mentions across 24 days

Affected systems

Vendors
Products
web_help_desk

1 version affected across 1 product

Deep dive

Activity timeline76 mentions / 24d
0471114Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-02-07: 2Mentions · 2026-02-08: 3Mentions · 2026-02-09: 8Mentions · 2026-02-10: 4Mentions · 2026-02-17: 1Mentions · 2026-02-18: 2Mentions · 2026-03-09: 4Mentions · 2026-03-10: 14Mentions · 2026-03-11: 7Mentions · 2026-03-12: 2Mentions · 2026-03-13: 3Mentions · 2026-03-14: 2Mentions · 2026-03-15: 3Mentions · 2026-03-16: 5Mentions · 2026-03-17: 4Mentions · 2026-03-18: 3Mentions · 2026-03-19: 1Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-04-17: 1Mentions · 2026-04-21: 2Mentions · 2026-08-17: 1PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-02-17: 1Exploit Tool / Code · 2026-02-09: 2Exploit Tool / Code · 2026-02-10: 1Exploit Tool / Code · 2026-02-18: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-02-07: 2Active Exploitation · 2026-02-08: 3Active Exploitation · 2026-02-09: 7Active Exploitation · 2026-02-10: 3Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-02-18: 2Active Exploitation · 2026-03-09: 2Active Exploitation · 2026-03-10: 10Active Exploitation · 2026-03-11: 6Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-03-14: 2Active Exploitation · 2026-03-15: 1Active Exploitation · 2026-03-16: 2Active Exploitation · 2026-03-17: 2Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-04-21: 2Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-02-08: 2Patch / Workaround · 2026-02-09: 2Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-03-10: 8Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-09: 3Technical Details · 2026-02-18: 1Technical Details · 2026-03-09: 2Technical Details · 2026-03-10: 7Technical Details · 2026-03-11: 4Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 2Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 2Technical Details · 2026-03-16: 4Technical Details · 2026-03-17: 2Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 1Technical Details · 2026-08-17: 101-2802-0702-0902-1703-0903-1103-1303-1503-1703-1903-2404-2108-17
Signal classification4 categories
Active Exploitation
4964.5%
Disclosure
1317.1%
General
810.5%
Patch
67.9%
Referenced assets52 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-281
General1
2026-01-291
Active Exploitation1
2026-02-072
Active Exploitation2
2026-02-083
Active Exploitation3
2026-02-098
Active Exploitation7General1
2026-02-104
Active Exploitation3Disclosure1
2026-02-171
Active Exploitation1
2026-02-182
Active Exploitation2
2026-03-094
Active Exploitation2Disclosure1General1
2026-03-1014
Active Exploitation10General2Patch2
2026-03-117
Active Exploitation5Disclosure1Patch1
2026-03-122
General1Patch1
2026-03-133
Active Exploitation1Disclosure1Patch1
2026-03-142
Active Exploitation2
2026-03-153
Active Exploitation1Disclosure1General1
2026-03-165
Active Exploitation1Disclosure3Patch1
2026-03-174
Active Exploitation2Disclosure2
2026-03-183
Active Exploitation1Disclosure1General1
2026-03-191
Disclosure1
2026-03-231
Active Exploitation1
2026-03-241
Active Exploitation1
2026-04-171
Active Exploitation1
2026-04-212
Active Exploitation2
2026-08-171
Disclosure1
Full discourse20 posts
  • RussianPanda 🐼 🇺🇦@RussianPanda9xx
    Active Exploitation

    New blog on a Sunday, sheesh… We caught threat actors actively exploiting SolarWinds Web Help Desk (CVE-2025-26399) The tradecraft is wild - Velociraptor as C2, Zoho Assist, Cloudflare tunnels, QEMU SSH backdoors, and the attacker built their own Elastic Cloud instance to triage victims at scale. Bro thinks he’s a blue teamer 💀 Patch WHD to 2026.1 now - all prior versions are vulnerable http://huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399

    Post summary

    A blog post reports that threat actors are actively exploiting CVE-2025-26399 in SolarWinds Web Help Desk, detailing their tradecraft and urging users to upgrade to version 2026.1.

    96762839833.1K
    18.3K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ CISA added 3 actively exploited flaws to KEV. Most critical: SolarWinds Web Help Desk CVE-2025-26399 (CVSS 9.8) allowing remote command execution. Other KEV entries hit Omnissa Workspace One UEM and Ivanti Endpoint Manager. Federal agencies ordered to patch. 🔗 Details → https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html

    Post summary

    CISA announced three actively exploited vulnerabilities—most notably SolarWinds Web Help Desk CVE‑2025‑26399 (CVSS 9.8)—added them to the KEV, and directed federal agencies to patch the flaws.

    0243831210.0K
    1.1M followersView on X
  • Jamie Levy🦉@gleeda
    Active Exploitation

    Do you have mad skills 🥷and want to join the Adversary Tactics team at @HuntressLabs ? We're looking for that special someone to help lead our Rapid Response engagements. Some examples of deliverables are: * SolarWinds Web Help Desk: https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399 * React2Shell: https://www.huntress.com/blog/peerblight-linux-backdoor-exploits-react2shell * Gladinet / Triofox: https://www.huntress.com/blog/cve-2025-30406-critical-gladinet-centrestack-triofox-vulnerability-exploited-in-the-wild * CrushFTP: https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation

    Post summary

    The text advertises a role that involves responding to real‑world attacks, citing CVEs that have been actively exploited in the wild.

    0231732317.7K
    9.8K followersView on X
  • Huntress@HuntressLabs
    Active Exploitation

    We investigated threat actors actively exploiting SolarWinds Web Help Desk (CVE-2025-26399)...and the tradecraft is unhinged. 🔎 If you run SolarWinds WHD, patch to 2026.1. Now. This write-up is only part of what we uncovered: https://okt.to/9MzvtP More to come. 👀

    Post summary

    Threat actors are actively exploiting SolarWinds Web Help Desk CVE‑2025‑26399; users are urged to patch to version 2026.1, with further details available in the linked write‑up.

    3131451310.7K
    38.5K followersView on X
  • John Hammond@_JohnHammond
    Active Exploitation

    hat tip to @RussianPanda9xx @gleeda at. al. @HuntressLabs 😎 https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399?utm_source=twitter&utm_medium=social&utm_campaign=cy26-q1-brand-na-broad-all-x&utm_content=Text https://t.co/aRYGEjOTLC

    Post summary

    The tweet links to a Huntress Labs article announcing that CVE‑2025‑26399 is actively being exploited in SolarWinds Web Help Desk.

    1614589.2K
    311.9K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Omnissa Workspace ONE UEM vulnerability CVE-2021-22054, SolarWinds Web Help Desk vulnerability CVE-2025-26399, & Ivanti Endpoint Manager vulnerability CVE-2026-1603 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/fcNCCfmzdF

    Post summary

    The tweet announces that three CVEs (CVE‑2021‑22054, CVE‑2025‑26399, CVE‑2026‑1603) have been added to the DHS KEV Catalog, indicating these vulnerabilities are being actively exploited, but it provides no technical details or patch information.

    11204216.8K
    292.6K followersView on X
  • Virus Bulletin@virusbtn
    Active Exploitation

    Huntress researchers Anna Pham, John Hammond & Jamie Levy observed threat actors exploiting a SolarWinds Web Help Desk vulnerability and warn organizations to apply the update from SolarWinds’ website as soon as possible. https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399 https://t.co/gH1uV46u64

    Post summary

    Huntress researchers confirmed that threat actors are actively exploiting CVE‑2025‑26399 in SolarWinds Web Help Desk and are urging immediate patching from SolarWinds’ website.

    1403162.6K
    60.8K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-26399 - critical 🚨 SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCE > SolarWinds Web Help Desk contains an unauthenticated AjaxProxy deserialization remote... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-26399 @pdnuclei #NucleiTemplates ...

    Post summary

    SolarWinds Web Help Desk versions below 12.8.7 are vulnerable to an unauthenticated AjaxProxy deserialization remote code execution (CVE-2025-26399); the tweet provides the vulnerability type but no PoC or patch information.

    090168790
    1.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/9追加) 🛡️No.1538 CVE-2021-22054 Omnissa Workspace ONE Server-Side Request Forgery ============= CVSSスコア: 7.5 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 種別:サーバサイドのリクエストフォージェリ (CWE-918 / CISA-ADP) 深刻度:重要 国内影響度判定(※):中 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートから細工されたリクエストを介して、機密情報にアクセスされる恐れがあります。(旧称:VMware Workspace One UEM) https://web.archive.org/web/20211222154335/https://www.vmware.com/security/advisories/VMSA-2021-0029.html 🛡️No.1539 CVE-2025-26399 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:信頼できないデータのデシリアライゼーション (CWE-502 / CISA-ADP) 深刻度:緊急🔥 国内影響度判定(※):高 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからホスト マシン上でコマンドを実行される恐れがあります。 https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399 🛡️No.1540 CVE-2026-1603 Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability ============= CVSSスコア: 8.6 (Base) / ivanti CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N 種別:代替パスまたはチャネルを使用した認証回避 (CWE-288 / ivanti) 深刻度:重要 国内影響度判定(※):中~高 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートから特定の保存された資格情報データを窃取される恐れがあります。 https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024 ※ ChatGPTによる判定結果。試験的に行っているもので、誤判定の可能性があります。 CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/03/09/cisa-adds-three-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has confirmed that three listed CVEs are actively exploited and has added them to the KEV catalog, providing basic technical details and links to vendor advisories that likely contain patches.

    020623.8K
    42.7K followersView on X
  • 中島佑允(YusukeNakajima)@nakajimeeee
    Active Exploitation

    【脆弱性悪用】SolarWinds Web Help Deskの積極的な悪用を確認、攻撃者は自前SIEMで被害者を管理 Huntressは、SolarWinds Web Help Desk(WHD)の脆弱性CVE-2025-26399を悪用した攻撃を3顧客で確認した。12.8.7 HF1より前の全バージョンが影響を受け、CISAのKEVカタログにも追加されている。攻撃は2026年1月16日から始まった可能性がある。 攻撃チェーンはWHDサービスプロセスから始まり、Catbox経由でZoho Assistをインストール後、Supabase上のVelociraptor(DFIR用ツール)をC2として展開する。興味深いのは、攻撃者が被害者のシステム情報をElastic Cloudの無料トライアルインスタンスに送信し、防御側が使うSIEMを「被害者管理ダッシュボード」として悪用している点である。 攻撃者はHTTP 406レスポンスをトリガーとしたC2フェイルオーバー機構を実装しており、Cloudflare Workersからバックアップドメインへ動的に切り替え可能である。また、QEMUを使用したSSHバックドアの永続化(TPMProfilerタスク)も確認された。対策として、WHDを2026.1以降へ更新し、管理インターフェースをVPN/ファイアウォール配下に置くことが推奨される。 https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399

    Post summary

    SolarWinds Web Help Desk CVE‑2025‑26399 has been actively exploited in the wild, with attackers employing a sophisticated chain of tools and techniques; a patch to version 2026.1 and network hardening are recommended.

    01071696
    2.4K followersView on X
  • Patrick Roland@DeusLogica
    Patch

    🔴 CISA KEV OVERDUE: SolarWinds Web Help Desk deserialization (CVE-2025-26399) Due date was TODAY. If you're running SolarWinds Web Help Desk and haven't patched, you're exposed. Command execution via AjaxProxy. Post-SUNBURST, we should know better. Thread on impact and remediation 👇

    Post summary

    The tweet highlights that SolarWinds Web Help Desk CVE-2025-26399 is an overdue CISA KEV with deserialization-based command execution via AjaxProxy, urging users to apply patches immediately.

    51110511
    330 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    🔥 CISA KEV: SolarWinds WHD RCE (CVE-2025-26399) SolarWinds Workflow Health Dashboard (WHD) Remote Code Execution vulnerability. This is a critical vulnerability in a widely used network management platform. Thread on what you need to know 👇

    Post summary

    The tweet announces that SolarWinds Workflow Health Dashboard is affected by CVE-2025-26399, an RCE vulnerability that has been identified as a known exploited vulnerability (CISA KEV), though it provides no PoC, exploit code, patch, or debunking information.

    5000083
    331 followersView on X
  • Patrick Roland@DeusLogica
    Disclosure

    🔥 CISA KEV: SolarWinds WHD RCE (CVE-2025-26399) SolarWinds Workflow Health Dashboard (WHD) Remote Code Execution vulnerability. This is a critical vulnerability in a widely used network management platform. Thread on what you need to know 👇

    Post summary

    The announcement highlights a critical RCE flaw in SolarWinds Workflow Health Dashboard, with no PoC, exploit, or patch details provided. The focus is on informing about the vulnerability’s existence and severity.

    5000094
    333 followersView on X
  • Patrick Roland@DeusLogica
    Disclosure

    🔥 CISA KEV: SolarWinds WHD RCE (CVE-2025-26399) SolarWinds Workflow Health Dashboard (WHD) Remote Code Execution vulnerability. This is a critical vulnerability in a widely used network management platform. Thread on what you need to know 👇

    Post summary

    The tweet alerts that CVE‑2025‑26399 is a critical RCE vulnerability in SolarWinds WHD, flagged as a CISA KEV, but it does not provide a PoC, exploit code, or patch details.

    5000090
    331 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    🔥 CISA KEV: SolarWinds WHD RCE (CVE-2025-26399) SolarWinds Workflow Health Dashboard (WHD) Remote Code Execution vulnerability. This is a critical vulnerability in a widely used network management platform. Thread on what you need to know 👇

    Post summary

    The tweet announces SolarWinds WHD CVE-2025-26399 as a CISA Known Exploited Vulnerability, confirming active exploitation but providing no PoC, exploit code, or patch details.

    50000171
    331 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Payouts King ransomware deploys QEMU VMs running Alpine Linux to evade endpoint detection and establish covert SSH tunnels. Campaign exploits SonicWall VPNs and CVE-2025-26399, linked to GOLD ENCOUNTER group and former BlackBasta affiliates. #DFIR_Radar https://t.co/mJVnw0plQU

    Post summary

    The tweet reports that the Payouts King ransomware campaign is actively exploiting CVE-2025-26399 in SonicWall VPNs, using QEMU VMs and covert SSH tunnels to evade detection.

    10011700
    1.7K followersView on X
  • Autumn Good@autumn_good_35
    Active Exploitation

    『In an ironic twist, the threat actor essentially built themselves a SIEM, using Elastic, no less -- to triage their victims.』😲 Active Exploitation of SolarWinds Web Help Desk https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399

    Post summary

    The post confirms that SolarWinds Web Help Desk CVE-2025-26399 is being actively exploited in the wild, with threat actors leveraging SIEM tools for victim triage.

    00111560
    6.7K followersView on X
  • 보안프로젝트@ngnicky
    Active Exploitation

    해커들이 SolarWinds Web Help Desk(WHD)의 취약점을 악용하여 Zoho ManageEngine 원격 모니터링 및 관리 도구와 같은 합법적인 도구를 악의적인 목적으로 배포 https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399

    Post summary

    Hackers are actively exploiting CVE-2025-26399 in SolarWinds Web Help Desk to distribute malicious payloads via legitimate management tools.

    01020184
    5.7K followersView on X
  • White Rabbitx@TheRabbitPy
    Active Exploitation

    🚨 CVE-2025-26399 (CVSS 9.8): SolarWinds Web Help Desk deserialization RCE—added to CISA KEV Mar 2026. Active cmd exec on helpdesks! https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html

    Post summary

    The text confirms that CVE‑2025‑26399 is actively exploited, with command execution confirmed on affected helpdesks and the vulnerability listed in the CISA KEV.

    01010122
    428 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    Sources: • CISA KEV: http://cisa.gov/known-exploited-vulnerabilities-catalog • SolarWinds Security Advisory: http://solarwinds.com/security • CVE-2025-26399: http://nvd.nist.gov/vuln/detail/CVE-2025-26399

    Post summary

    The text references CVE-2025-26399 along with the CISA Known Exploited Vulnerabilities catalog and a SolarWinds advisory, suggesting the vulnerability is being actively exploited, yet provides no PoC, patch, or technical detail.

    0101090
    331 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsweb_help_desk---
Appsolarwindsweb_help_desk12.8.7--

Explore more