Active Exploitation
#threatreport #HighCompleteness
Active Exploitation of SolarWinds Web Help Desk | 17-02-2026
Source: https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399
Key details below ↓
💀Threats:
Zoho_assist_tool, Cloudflared_tool, X2anylock, Toolshell_vuln, Bitsadmin_tool,
🎯Victims: Solarwinds web help desk users
🏭Industry: Transport
🔓CVEs: CVE-2025-26399 \[[Vulners](https://vulners.com/cve/CVE-2025-26399)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: Unknown
Soft:
- solarwinds web_help_desk (le12.8.6, 12.8.7)
CVE-2025-40551 \[[Vulners](https://vulners.com/cve/CVE-2025-40551)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- solarwinds web_help_desk (<2026.1)
CVE-2025-40536 \[[Vulners](https://vulners.com/cve/CVE-2025-40536)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- solarwinds web_help_desk (<2026.1)
📚TTPs:
⚔️Tactics: 5
🛠️Technics: 3
🧨IOCs:
- Path: 7
- File: 13
- Url: 5
- Coin: 1
- Command: 1
- Registry: 2
- Domain: 2
- Hash: 4
💽Software: Windows Defender, Windows Firewall, Supabase, Velociraptor, QEMU, WebhubDesk, Active Directory, linux, Windows service, Kibana, ...
🔢Algorithms: sha256, base64
🔠Functions: Get-FileHash, Get-ComputerInfo, Set-Content, Write-Host
⚙️Win Services: BITS
📜Programming Languages: powershell, java
💻Platforms: intel, amd64
SIGMA: Found
#threatreport:
The active exploitation of SolarWinds Web Help Desk has been observed with a notable attack chain initiated by a threat actor leveraging wrapper.exe, which is the Web Help Desk service wrapper. This process subsequently spawned a Java executable (java.exe), which is tied to the underlying Tomcat-based application of the Web Help Desk. Following this, the Java process executed a command to install a remote MSI payload silently via cmd.exe.
To facilitate command and control, the attacker utilized Velociraptor, a tool typically aimed at defenders for endpoint monitoring and artifact collection but repurposed here for malicious activities. The first command from Velociraptor involved a hash check of an existing file, signifying reconnaissance efforts early in the intrusion phase. The attacker also installed Cloudflared from GitHub to create direct connection tunnels for command and control purposes.
As part of its operational strategy, the threat actor executed a PowerShell script shortly after gaining access, which gathered extensive system information and transmitted it to an attacker-managed Elastic Cloud instance. This indicates a sophisticated layer of data exfiltration aimed at consolidating intelligence on the compromised system. Additionally, a command for implementing a live C2 failover mechanism was executed around the same time as the download of Visual Studio Code, which is notable for enhancing the resilience of the attacker's infrastructure. Further reconnaissance was performed using the systeminfo command, potentially as a redundancy measure for data collection.
Moreover, persistence mechanisms were observed in the form of the creation of a scheduled task known as TPMProfiler, commonly associated with exploitation scenarios and representing a false legitimate administrative task.
For mitigation, it is recommended that organizations operating SolarWinds Web Help Desk update to version 2026.1 or later, addressing critical vulnerabilities identified as CVE-2025-26399, CVE-2025-40536, and CVE-2025-40551. Administrators should ensure that the WHD administrative interfaces are not publicly exposed, ideally placing it behind a VPN or firewall. Comprehensive security measures, including password resets for service accounts and the removal of unauthorized remote access tools and unexpected service instances, are necessary to reduce exposure to such threats.
The entire attack chain evidences malicious exploitation of the SolarWinds platform, utilizing common tools in unexpected ways to maintain command privileges and gather intelligence, underscoring the necessity for constant vigilance and proactive defense measures within impacted infrastructure.
Post summary
The report confirms active exploitation of SolarWinds Web Help Desk CVEs CVE-2025-26399, CVE-2025-40551, and CVE-2025-40536, detailing the attack chain and providing patch and mitigation guidance.