CVE-2025-40536Active Exploitation(solarwinds / web_help_desk)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (10 mentions)

Immediate actions

  • Patch solarwinds web_help_desk systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-15. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-693

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_help_desk

Threat summary

  • Active exploitation appears in 21 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 39 mentions across 15 observed days

What's happening

  • Active exploitation reported across 21 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 18 signals
  • Technical details provided in 31 signals
  • Disclosure: 9 classified signals
  • Peaked at 10 mentions on most recent observed day (2026-02-18)
  • 39 total mentions across 15 days

Affected systems

Vendors
Products
web_help_desk

Deep dive

Activity timeline39 mentions / 15d
035810Mentions · 2026-01-28: 2Mentions · 2026-01-29: 2Mentions · 2026-01-30: 4Mentions · 2026-02-02: 1Mentions · 2026-02-05: 1Mentions · 2026-02-07: 3Mentions · 2026-02-08: 1Mentions · 2026-02-09: 2Mentions · 2026-02-10: 1Mentions · 2026-02-12: 3Mentions · 2026-02-13: 6Mentions · 2026-02-14: 1Mentions · 2026-02-15: 1Mentions · 2026-02-16: 1Mentions · 2026-02-18: 10PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-01-30: 1PoC Mentioned / Linked · 2026-02-13: 1Exploit Tool / Code · 2026-01-29: 1Exploit Tool / Code · 2026-01-30: 1Exploit Tool / Code · 2026-02-18: 2Active Exploitation · 2026-02-07: 3Active Exploitation · 2026-02-09: 2Active Exploitation · 2026-02-10: 1Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-02-13: 6Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-15: 1Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-02-18: 5Patch / Workaround · 2026-01-29: 2Patch / Workaround · 2026-01-30: 2Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-13: 5Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-02-18: 3Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 2Technical Details · 2026-01-30: 4Technical Details · 2026-02-02: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-07: 2Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 2Technical Details · 2026-02-10: 1Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 4Technical Details · 2026-02-14: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-18: 701-2801-2901-3002-0202-0502-0702-0802-0902-1002-1202-1302-1402-1502-1602-18
Signal classification5 categories
Active Exploitation
2051.3%
Disclosure
923.1%
Patch
410.3%
Exploit
37.7%
General
37.7%
Referenced assets39 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-282
Disclosure2
2026-01-292
Exploit1Patch1
2026-01-304
Disclosure1Exploit1Patch2
2026-02-021
Disclosure1
2026-02-051
Disclosure1
2026-02-073
Active Exploitation3
2026-02-081
Disclosure1
2026-02-092
Active Exploitation2
2026-02-101
Active Exploitation1
2026-02-123
Active Exploitation1Disclosure1General1
2026-02-136
Active Exploitation5Patch1
2026-02-141
Active Exploitation1
2026-02-151
Active Exploitation1
2026-02-161
Active Exploitation1
2026-02-1810
Active Exploitation5Disclosure2Exploit1General2
Full discourse20 posts
  • Stephen Fewer@stephenfewer
    Exploit

    We now have a draft @metasploit module for the recent SolarWinds Web Help Desk vulns (CVE-2025-40536 + CVE-2025-40551) , based on the PoC by @Horizon3ai but with a gadget for loading native code modules to achieve RCE: https://github.com/rapid7/metasploit-framework/pull/20917

    Post summary

    A draft Metasploit module for SolarWinds Web Help Desk CVEs 2025‑40536 and 2025‑40551 has been released, featuring a gadget to load native code modules and achieve remote code execution.

    016069268.4K
    9.6K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA added one more vulnerability to the KEV Catalog today... CVE-2025-40536: SolarWinds Web Help Desk Security Control Bypass Vulnerability: SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.

    Post summary

    CISA has added CVE-2025-40536 to the KEV catalog, noting a security control bypass in SolarWinds Web Help Desk that could let unauthenticated attackers access restricted functions.

    1301354.6K
    164.8K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/12追加) 🛡️No.1515 CVE-2024-43468 Microsoft Configuration Manager SQL Injection Vulnerability ============= CVSSスコア: 9.8 (Base) / Microsoft Corporation CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:SQLインジェクション (CWE-89 / Microsoft Corporation) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたリクエストを受信することで、サーバーや基盤となるデータベース上でコマンドを実行される恐れがあります。 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43468 🛡️No.1516 CVE-2025-15556 Notepad++ Download of Code Without Integrity Check Vulnerability ============= CVSSスコア: 7.7 (Base) / VulnCheck CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 種別:ダウンロードしたコードの完全性検証不備 (CWE-494 / VulnCheck) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、アップデートトラフィックを傍受またはリダイレクトして、攻撃者が制御するインストーラをダウンロード・実行される恐れがあります。この脆弱性を悪用することで、ユーザー権限で任意のコードが実行される可能性があります。 https://notepad-plus-plus.org/news/clarification-security-incident/ https://community.notepad-plus-plus.org/topic/27298/notepad-v8-8-9-vulnerability-fix 🛡️No.1517 CVE-2025-40536 SolarWinds Web Help Desk Security Control Bypass Vulnerability ============= CVSSスコア: 8.1 (Base) / SolarWinds CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:保護メカニズムの不具合 (CWE-693 / SolarWinds) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートから制限された特定機能にアクセスされる恐れがあります。 https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40536 🛡️No.1518 CVE-2026-20700 Apple Multiple Buffer Overflow Vulnerability ============= CVSSスコア: 7.8 (Base) / CISA-ADP CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:バッファエラー (CWE-119 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: メモリへの書き込み権限を持つ攻撃者により、ローカル上で任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/126346 https://support.apple.com/en-us/126348 https://support.apple.com/en-us/126351 https://support.apple.com/en-us/126352 https://support.apple.com/en-us/126353 CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post announces that CISA confirmed exploitation of four CVEs, providing technical details and links to vendor patches, emphasizing the active exploitation status.

    000803.7K
    42.5K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    SolarWinds Web Help Desk の脆弱性 CVE-2025-40536/40537/40551:連鎖による RCE の恐れ https://iototsecnews.jp/2026/01/29/solarwinds-web-product-flaw-allows-attackers-to-bypass-security-and-execute-code/ SolarWinds の IT サービス管理プラットフォーム Web Help Desk において、認証を一切必要とせずにサーバ上で任意のコマンド実行を可能にする、きわめて深刻な脆弱性チェーンが公開されました。この攻撃は、http://Horizon3.ai の研究者により特定された、3 つの脆弱性を組み合わせることで成立します。特筆すべきは、過去に何度も修正されてきた問題を、再び回避する手法が用いられ、深刻な侵害に至る点です。ご利用のチームは、ご注意ください。 #CVE202540536 #CVE202540537 #CVE202540551 #SolarWinds #Vulnerability #WebHelpDesk

    Post summary

    A severe, authentication‑bypass remote code execution vulnerability chain (CVE-2025-40536/37/51) in SolarWinds Web Help Desk has been publicly disclosed, with no mention of active exploitation, PoC, or patches.

    02021239
    483 followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    The @CISAgov added 4 exploited bugs to KEV: SolarWinds WHD (CVE-2025-40536, 9.8), MS ConfigMgr SQLi→RCE (CVE-2024-43468, 9.8), Apple (CVE-2026-20700), Notepad++ (CVE-2025-15556). Patch fast. #cybersecurity #CISO #infosec #ITsecurity https://bit.ly/4azGT9e

    Post summary

    CISA added four CVEs to its KEV list, confirming they are actively exploited and urging rapid patching.

    020201.8K
    119.3K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    Static Creds (CVE-2025-40537) Security Protection Bypass (CVE-2025-40536) Java Deserialization (CVE-2025-40551) CVE-2025-40551: Another Solarwinds Web Help Desk Deserialization Issue https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/

    Post summary

    The text announces several new CVEs, including CVE-2025-40551, a Java deserialization flaw affecting SolarWinds Web Help Desk, and links to an associated research article.

    101201.7K
    6.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Patch

    SolarWinds、認証バイパス/RCEなど複数の重大脆弱性を修正(CVE-2025-40536/40537/40551/40552/40553/40554)|セキュリティ対策Lab https://rocket-boys.co.jp/security-measures-lab/solarwinds-fixes-multiple-critical-vulnerabilities-auth-bypass-rce-cve-2025/ "認証バイパスや未認証で悪用可能なリモートコード実行(RCE)を含む複数の脆弱性 修正が含まれます"

    Post summary

    The post announces the release of patch corrections for several critical SolarWinds vulnerabilities, including authentication bypass and unauthenticated remote code execution.

    11011288
    3.4K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit #AppSec 1⃣. SolarWinds WHD RCE https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/ // Critical vulnerabilities in Solarwinds Web Help Desk (CVE-2025-40551, CVE-2025-40537, CVE-2025-40536) allow unauthenticated RCE through deserialization and request bypasses, with patches available in ver.2026.1 2⃣. CVE-2026-21509 - MS Office 0-Day https://github.com/Ashwesker/Ashwesker-CVE-2026-21509 ]-> Security Update Guide https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 // Reliance on untrusted inputs in a security decision in MS Office allows an unauth attacker to bypass a security feature locally 3⃣. Bypassing Windows Administrator Protection https://projectzero.google/2026/26/windows-administrator-protection.html // As of 1st Dec. 2025 the Administrator Protection feature has been disabled by Microsoft while an application compatibility issue is dealt with

    Post summary

    The post lists several critical CVEs, links to PoC and exploit code repositories, and notes available patches, but does not indicate current active exploitation.

    01030447
    3.1K followersView on X
  • transilienceai@transilienceai
    Patch

    @ohhara_shiojiri ⚠️ **CVE-2025-40536** is a security control bypass vulnerability in SolarWinds Web Help Desk, also added to CISA KEV. Patch promptly, as it joins other exploited issues requiring immediate attention. #SolarWinds #VulnerabilityAlert

    Post summary

    CVE-2025-40536, a security control bypass in SolarWinds Web Help Desk, has been added to the CISA KEV and requires immediate patching.

    2000041
    315 followersView on X
  • 보안프로젝트@ngnicky
    Active Exploitation

    Microsoft Defender 연구팀은 SolarWinds Web Help Desk(WHD)의 취약점을 악용한 실제 공격 사례를 발견 현재 추가 조사를 통해 악용된 실제 취약점( CVE-2025-40551 (신뢰할 수 없는 데이터 역직렬화), CVE-2025-40536 (보안 제어 우회), CVE-2025-26399 등)을 확인 https://www.microsoft.com/en-us/security/blog/2026/02/06/active-exploitation-solarwinds-web-help-desk/ https://t.co/lGoj3EE0N0

    Post summary

    Microsoft Defender has confirmed real-world exploitation of SolarWinds Web Help Desk using multiple CVEs, with details posted in a Microsoft Security Blog.

    00002173
    5.8K followersView on X
  • RedPacket Security@RedPacketSec
    Active Exploitation

    Analysis of active exploitation of SolarWinds Web Help Desk - https://www.redpacketsecurity.com/analysis-of-active-exploitation-of-solarwinds-web-help-desk/ #threatintel #solarwinds-web-help-desk #cve-2025-40551 #cve-2025-40536 #cve-2025-26399 #rce-exploitation

    Post summary

    Red Packet Security reports ongoing real‑world attacks against SolarWinds Web Help Desk involving CVE‑2025‑40551, CVE‑2025‑40536, and CVE‑2025‑26399, confirming active exploitation in the wild.

    01010123
    3.5K followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #HighCompleteness Active Exploitation of SolarWinds Web Help Desk | 17-02-2026 Source: https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399 Key details below ↓ 💀Threats: Zoho_assist_tool, Cloudflared_tool, X2anylock, Toolshell_vuln, Bitsadmin_tool, 🎯Victims: Solarwinds web help desk users 🏭Industry: Transport 🔓CVEs: CVE-2025-26399 \[[Vulners](https://vulners.com/cve/CVE-2025-26399)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - solarwinds web_help_desk (le12.8.6, 12.8.7) CVE-2025-40551 \[[Vulners](https://vulners.com/cve/CVE-2025-40551)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - solarwinds web_help_desk (<2026.1) CVE-2025-40536 \[[Vulners](https://vulners.com/cve/CVE-2025-40536)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - solarwinds web_help_desk (<2026.1) 📚TTPs: ⚔️Tactics: 5 🛠️Technics: 3 🧨IOCs: - Path: 7 - File: 13 - Url: 5 - Coin: 1 - Command: 1 - Registry: 2 - Domain: 2 - Hash: 4 💽Software: Windows Defender, Windows Firewall, Supabase, Velociraptor, QEMU, WebhubDesk, Active Directory, linux, Windows service, Kibana, ... 🔢Algorithms: sha256, base64 🔠Functions: Get-FileHash, Get-ComputerInfo, Set-Content, Write-Host ⚙️Win Services: BITS 📜Programming Languages: powershell, java 💻Platforms: intel, amd64 SIGMA: Found #threatreport: The active exploitation of SolarWinds Web Help Desk has been observed with a notable attack chain initiated by a threat actor leveraging wrapper.exe, which is the Web Help Desk service wrapper. This process subsequently spawned a Java executable (java.exe), which is tied to the underlying Tomcat-based application of the Web Help Desk. Following this, the Java process executed a command to install a remote MSI payload silently via cmd.exe. To facilitate command and control, the attacker utilized Velociraptor, a tool typically aimed at defenders for endpoint monitoring and artifact collection but repurposed here for malicious activities. The first command from Velociraptor involved a hash check of an existing file, signifying reconnaissance efforts early in the intrusion phase. The attacker also installed Cloudflared from GitHub to create direct connection tunnels for command and control purposes. As part of its operational strategy, the threat actor executed a PowerShell script shortly after gaining access, which gathered extensive system information and transmitted it to an attacker-managed Elastic Cloud instance. This indicates a sophisticated layer of data exfiltration aimed at consolidating intelligence on the compromised system. Additionally, a command for implementing a live C2 failover mechanism was executed around the same time as the download of Visual Studio Code, which is notable for enhancing the resilience of the attacker's infrastructure. Further reconnaissance was performed using the systeminfo command, potentially as a redundancy measure for data collection. Moreover, persistence mechanisms were observed in the form of the creation of a scheduled task known as TPMProfiler, commonly associated with exploitation scenarios and representing a false legitimate administrative task. For mitigation, it is recommended that organizations operating SolarWinds Web Help Desk update to version 2026.1 or later, addressing critical vulnerabilities identified as CVE-2025-26399, CVE-2025-40536, and CVE-2025-40551. Administrators should ensure that the WHD administrative interfaces are not publicly exposed, ideally placing it behind a VPN or firewall. Comprehensive security measures, including password resets for service accounts and the removal of unauthorized remote access tools and unexpected service instances, are necessary to reduce exposure to such threats. The entire attack chain evidences malicious exploitation of the SolarWinds platform, utilizing common tools in unexpected ways to maintain command privileges and gather intelligence, underscoring the necessity for constant vigilance and proactive defense measures within impacted infrastructure.

    Post summary

    The report confirms active exploitation of SolarWinds Web Help Desk CVEs CVE-2025-26399, CVE-2025-40551, and CVE-2025-40536, detailing the attack chain and providing patch and mitigation guidance.

    10000101
    583 followersView on X
  • transilienceai@transilienceai
    General

    @dailycve Related CVEs in the same cluster include critical RCEs (CVE-2025-40551/40553, CVSS 9.8) and hardcoded credentials (CVE-2025-40537). No public exploits for CVE-2025-40536 alone were detailed, but it facilitates broader attacks. #VulnerabilityManagement

    Post summary

    The tweet lists related CVEs, noting critical RCEs and hardcoded credentials, but provides no PoC, exploit code, patch, or active exploitation details.

    1000047
    313 followersView on X
  • transilienceai@transilienceai
    Exploit

    @dailycve - Initial Access: Possible SolarWinds WHD RCE exploit; Trojan:Win32/HijackWebHelpDesk.A; MDVM for CVE-2025-40536/40551.

    Post summary

    The tweet reports a potential SolarWinds WHD remote code execution vulnerability (CVE-2025-40536/40551) and references an MDVM exploit tool, signaling a risk of exploitation in the wild.

    1000063
    313 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    @dailycve Microsoft observed real-world attacks starting December 2025 on internet-facing WHD instances. Initial access involved CVE-2025-40536, CVE-2025-40551, or CVE-2025-26399. #MalwareAlert

    Post summary

    Microsoft reports that real‑world attacks began in December 2025 against internet‑facing WHD instances, using CVE-2025-40536, CVE-2025-40551, or CVE-2025-26399 as initial access vectors.

    1000049
    313 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    CVE-2025-40536 is a high-severity (CVSS 8.1) security control bypass vulnerability in SolarWinds Web Help Desk (WHD), allowing unauthenticated attackers to access restricted functionality. 🚨 It has been actively exploited in the wild alongside other flaws like CVE-2025-40551, leading to remote code execution (RCE), lateral movement, and potential domain compromise. #CyberSecurity #Vulnerability

    Post summary

    CVE‑2025‑40536 is a high‑severity control‑bypass flaw in SolarWinds Web Help Desk that has been actively exploited in the wild, enabling attackers to achieve remote code execution and lateral movement.

    1000053
    313 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 #SolarWinds, Security Control Bypass, #CVE-2025-40536 (HIGH) https://dailycve.com/solarwinds-security-control-bypass-cve-2025-40536-high/

    Post summary

    The message announces the high‑severity SolarWinds CVE‑2025‑40536 as a security control bypass but provides no PoC, exploit code, or mitigation details.

    1000041
    162 followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    The @CISAgov added 4 exploited bugs to KEV: SolarWinds WHD (CVE-2025-40536, 9.8), MS ConfigMgr SQLi→RCE (CVE-2024-43468, 9.8), Apple (CVE-2026-20700), Notepad++ (CVE-2025-15556). Patch fast. #cybersecurity #CISO #infosec #ITsecurity https://bit.ly/4azGT9e

    Post summary

    CISA has added four CVEs to its KEV list, confirming they are actively exploited. Patches are available and should be applied promptly.

    00010421
    119.3K followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、既知の悪用された脆弱性4件をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Feb 12) CVE-2024-43468 Microsoft Configuration Manager の SQL インジェクション脆弱性 CVE-2025-15556 Notepad++ における整合性チェックなしのコードダウンロードの脆弱性 CVE-2025-40536 SolarWinds Webヘルプデスクのセキュリティ制御バイパスの脆弱性 CVE-2026-20700 Appleの複数のバッファオーバーフロー脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/12/cisa-adds-four-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced the addition of four CVEs—Microsoft, Notepad++, SolarWinds, and Apple—to its catalog of known exploited vulnerabilities, confirming active exploitation while providing only basic technical details and no patch or PoC information.

    00010321
    4.7K followersView on X
  • Cyber News Live@cybernewslive
    Active Exploitation

    Attackers are exploiting SolarWinds Web Help Desk (WHD) using a chain of vulnerabilities, including two zero-days (vulnerabilities CVE-2025-40551 and CVE-2025-40536). These flaws allow remote code execution and authentication bypass. If you use SolarWinds WHD, update to the latest version immediately. 🔥 #CyberNewsLive https://csoonline.com/article/4130151/solarwinds-whd-zero-days-from-january-are-under-attack.html

    Post summary

    The post reports that attackers are actively exploiting two zero‑day vulnerabilities (CVE‑2025‑40551 and CVE‑2025‑40536) in SolarWinds Web Help Desk to achieve remote code execution and authentication bypass, and urges users to update immediately.

    0100096
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsweb_help_desk---

Explore more