CVE-2025-40537Disclosure(solarwinds / web_help_desk)

MEDIUMCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch solarwinds web_help_desk systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_help_desk

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-01-30); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
web_help_desk

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-01-28: 2Mentions · 2026-01-29: 1Mentions · 2026-01-30: 3Mentions · 2026-02-02: 1Mentions · 2026-02-03: 1Mentions · 2026-02-18: 1PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-02-03: 1Exploit Tool / Code · 2026-01-29: 1Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-01-30: 2Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 1Technical Details · 2026-01-30: 2Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-18: 101-2801-2901-3002-0202-0302-18
Signal classification4 categories
Disclosure
333.3%
General
333.3%
Patch
222.2%
Exploit
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-01-282
Disclosure1General1
2026-01-291
Exploit1
2026-01-303
General1Patch2
2026-02-021
Disclosure1
2026-02-031
Disclosure1
2026-02-181
General1
Full discourse9 posts
  • Autumn Good@autumn_good_35
    General

    Static Creds (CVE-2025-40537) Security Protection Bypass (CVE-2025-40536) Java Deserialization (CVE-2025-40551) CVE-2025-40551: Another Solarwinds Web Help Desk Deserialization Issue https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/

    Post summary

    The post lists three CVEs and provides a link to a writeup on CVE‑2025‑40551 but does not supply any technical, exploit, or mitigation details.

    101201.7K
    6.7K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit #AppSec 1⃣. SolarWinds WHD RCE https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/ // Critical vulnerabilities in Solarwinds Web Help Desk (CVE-2025-40551, CVE-2025-40537, CVE-2025-40536) allow unauthenticated RCE through deserialization and request bypasses, with patches available in ver.2026.1 2⃣. CVE-2026-21509 - MS Office 0-Day https://github.com/Ashwesker/Ashwesker-CVE-2026-21509 ]-> Security Update Guide https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509 // Reliance on untrusted inputs in a security decision in MS Office allows an unauth attacker to bypass a security feature locally 3⃣. Bypassing Windows Administrator Protection https://projectzero.google/2026/26/windows-administrator-protection.html // As of 1st Dec. 2025 the Administrator Protection feature has been disabled by Microsoft while an application compatibility issue is dealt with

    Post summary

    The post highlights critical SolarWinds and MS Office vulnerabilities, links to PoC research, provides exploit code references, and notes available patches.

    01030447
    3.1K followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2025-40537 : SOLARWINDS WEB HELP DESK HARDCODED CREDENTIALS AUTH BYPASS ALERT 🚨 @solarwinds  A hardcoded credentials vulnerability has been identified in SolarWinds Web Help Desk (WHD) — allowing attackers to achieve an authentication bypass in certain scenarios by leveraging embedded/static credentials. Risk Severity: High (public reporting indicates strong attacker interest; patch available; treat internet-exposed WHD as urgent). Impact: • Unauthorized access to Web Help Desk via credential-based auth bypass conditions[ citation:1] • Administrative takeover risk depending on how the hardcoded credential path maps to roles/privileges in your deployment[ citation:5] • Exposure of sensitive ticket data (PII, incident details, password resets, internal system info) • Pivot opportunities via integrations (directory services/email/IT ops workflows) if the WHD instance is trusted internally[ citation:5] Root Cause: CWE-798 (Use of Hard-coded Credentials) WHD contains static credentials embedded in the application that can remain usable under certain conditions, undermining normal authentication controls and enabling unauthorized login. Attackers can: • Identify exposed WHD instances through scanning and fingerprinting (commonly web-accessible deployments) • Attempt authentication using the hardcoded credential pathway described for CVE-2025-40537 • Gain access to the WHD UI/API and enumerate tickets, users, and configuration[ citation:2] • Use the help desk as a foothold for broader internal abuse (data theft, phishing via tickets, abuse of trusted integrations) Are You Affected? Vulnerable: • SolarWinds Web Help Desk versions affected by CVE-2025-40537 (vendor/public advisories indicate impacted builds prior to the fixed release). Fixed in: • Update to the vendor-fixed release (commonly reported as WHD 12.8.1 / January 2026 security release stream—validate exact fixed build per SolarWinds advisory and your package channel). Note: This issue is frequently discussed alongside other WHD bugs (including critical RCEs). If you run WHD, you should assume multi-CVE patch urgency and update comprehensively, not selectively. Immediate Action Required: Update/Patch: • Upgrade WHD to the latest patched version provided by SolarWinds (e.g., 12.8.1 or newer as applicable) and confirm the deployed build matches the fixed release notes. Mitigation (if you can’t patch today): • Restrict access immediately: allowlist VPN/jump hosts only; block direct internet exposure at the firewall/reverse proxy. • Add temporary detections/controls for suspicious authentication attempts and admin session creation (stopgap, not a fix). Audit & Monitor: • Review authentication logs for anomalous successful logins and unusual admin actions (ticket exports, user/role changes, integration config edits). • Hunt for indicators of compromise in the WHD host (webshells, new scheduled tasks, suspicious outbound traffic), especially since WHD patch releases may address additional RCE issues. Incident Response: • If exposed, treat as potentially compromised: isolate the server, preserve forensic snapshots, rotate credentials that could be exposed via tickets/integrations, and review connected systems for lateral movement. Hardcoded credentials in an ITSM platform is a direct path to sensitive operational data and privileged workflows—patching and access restriction should be priority one. 🛡️ #solarwinds #security #ostorlabCVE

    Post summary

    SolarWinds Web Help Desk CVE-2025-40537 exposes hardcoded credentials that allow authentication bypass. The advisory stresses urgent patching to the 12.8.1 release and recommends access restrictions for exposed instances.

    01010128
    581 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    ⚠️⚠️⚠️ 『under certain situations, could allow access to administrative functions.』 SolarWinds Web Help Desk Hardcoded Credentials Vulnerability (CVE-2025-40537) https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40537

    Post summary

    The text announces the SolarWinds Web Help Desk hardcoded credentials vulnerability (CVE‑2025‑40537), noting that under specific circumstances it could grant administrative access.

    10010726
    6.7K followersView on X
  • transilienceai@transilienceai
    General

    @dailycve Related CVEs in the same cluster include critical RCEs (CVE-2025-40551/40553, CVSS 9.8) and hardcoded credentials (CVE-2025-40537). No public exploits for CVE-2025-40536 alone were detailed, but it facilitates broader attacks. #VulnerabilityManagement

    Post summary

    The tweet highlights CVE‑2025‑40536 as part of a cluster of critical RCEs and hardcoded credential issues, but does not provide exploits, patches, or active exploitation reports.

    1000047
    313 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚠️ CVE-2025-40537: SolarWinds Web Help Desk Hardco... Hardcoded creds in SolarWinds WHD (again) grant admin access with network reach - perfect for lateral movement post-ini... https://zerodaysignal.com/vulnerability/CVE-2025-40537 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    SolarWinds Web Help Desk contains hardcoded credentials that grant admin access and allow lateral movement, as disclosed in CVE-2025-40537; no evidence of active exploitation, patch, or PoC code is provided in the text.

    0000073
    132 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-40537 (CVSS:7.5, HIGH) is Undergoing Analysis. SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situat..https://nvd.nist.gov/vuln/detail/CVE-2025-40537 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a hardcoded credentials flaw in SolarWinds Web Help Desk (CVE‑2025‑40537) with a CVSS score of 7.5, but does not provide evidence of exploitation or remediation.

    00000124
    171 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Fixes Critical Web Help Desk Bugs Enabling Auth Bypass and Remote Code Execution SolarWinds patched multiple WHD flaws (fixed in Web Help Desk 2026.1) including auth bypass (CVE-2025-40552, CVE-2025-40554) and unsafe deserialization RCE (CVE-2025-40553, CVE-2025-40551), plus a hardcoded-credentials issue (CVE-2025-40537), making exposed deployments urgent to upgrade due to historical rapid exploitation patterns. 🎯 Target: Global/Organizations using SolarWinds Web Help Desk #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/solarwinds-patches-critical-vulnerabilities-in-web-help-desk-software

    Post summary

    SolarWinds released a patch for Web Help Desk fixing several critical vulnerabilities, including auth bypass and RCE, and urges organizations to upgrade quickly due to past rapid exploitation patterns.

    00000101
    196 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2025-40537 - SolarWinds - Web Help Desk - https://www.redpacketsecurity.com/cve-alert-cve-2025-40537-solarwinds-web-help-desk/ #OSINT #ThreatIntel #CyberSecurity #cve-2025-40537 #solarwinds #web-help-desk

    Post summary

    The post merely announces CVE-2025-40537 for SolarWinds Web Help Desk and links to an alert page, providing no further technical or threat information.

    00000106
    3.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsweb_help_desk---

Explore more