CVE-2025-40551Active Exploitation(solarwinds / web_help_desk)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 42 mentions and remains active

Immediate actions

  • Patch solarwinds web_help_desk systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-06. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_help_desk

Threat summary

  • Active exploitation appears in 78 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 133 mentions across 20 observed days

What's happening

  • Active exploitation reported across 78 signals
  • Exploit tool or code specified in 11 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 58 signals
  • Technical details provided in 98 signals
  • Disclosure: 24 classified signals
  • General: 14 classified signals
  • Peaked 14d ago at 42 mentions (2026-02-04); latest day: 1
  • 133 total mentions across 20 days

Affected systems

Vendors
Products
web_help_desk

Deep dive

Activity timeline133 mentions / 20d
011213242Mentions · 2026-01-28: 13Mentions · 2026-01-29: 6Mentions · 2026-01-30: 6Mentions · 2026-02-02: 1Mentions · 2026-02-03: 9Mentions · 2026-02-04: 42Mentions · 2026-02-05: 16Mentions · 2026-02-06: 4Mentions · 2026-02-07: 6Mentions · 2026-02-08: 2Mentions · 2026-02-09: 6Mentions · 2026-02-10: 4Mentions · 2026-02-11: 2Mentions · 2026-02-12: 3Mentions · 2026-02-18: 7Mentions · 2026-02-19: 1Mentions · 2026-02-24: 2Mentions · 2026-02-25: 1Mentions · 2026-03-05: 1Mentions · 2026-03-26: 1PoC Mentioned / Linked · 2026-01-28: 6PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-01-30: 2PoC Mentioned / Linked · 2026-02-03: 1PoC Mentioned / Linked · 2026-02-08: 1PoC Mentioned / Linked · 2026-02-09: 1PoC Mentioned / Linked · 2026-02-18: 1Exploit Tool / Code · 2026-01-28: 2Exploit Tool / Code · 2026-01-29: 1Exploit Tool / Code · 2026-01-30: 2Exploit Tool / Code · 2026-02-09: 1Exploit Tool / Code · 2026-02-10: 1Exploit Tool / Code · 2026-02-18: 2Exploit Tool / Code · 2026-02-19: 1Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-02-03: 4Active Exploitation · 2026-02-04: 33Active Exploitation · 2026-02-05: 11Active Exploitation · 2026-02-06: 4Active Exploitation · 2026-02-07: 4Active Exploitation · 2026-02-08: 1Active Exploitation · 2026-02-09: 5Active Exploitation · 2026-02-10: 3Active Exploitation · 2026-02-11: 2Active Exploitation · 2026-02-12: 2Active Exploitation · 2026-02-18: 4Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-02-24: 2Active Exploitation · 2026-02-25: 1Patch / Workaround · 2026-01-28: 4Patch / Workaround · 2026-01-29: 2Patch / Workaround · 2026-01-30: 2Patch / Workaround · 2026-02-03: 3Patch / Workaround · 2026-02-04: 25Patch / Workaround · 2026-02-05: 8Patch / Workaround · 2026-02-06: 4Patch / Workaround · 2026-02-07: 2Patch / Workaround · 2026-02-09: 2Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-11: 2Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-18: 2Technical Details · 2026-01-28: 12Technical Details · 2026-01-29: 5Technical Details · 2026-01-30: 4Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 9Technical Details · 2026-02-04: 31Technical Details · 2026-02-05: 12Technical Details · 2026-02-06: 3Technical Details · 2026-02-07: 3Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 6Technical Details · 2026-02-10: 1Technical Details · 2026-02-12: 3Technical Details · 2026-02-18: 5Technical Details · 2026-02-25: 1Technical Details · 2026-03-26: 101-2801-3002-0302-0502-0702-0902-1102-1802-2403-0503-26
Signal classification6 categories
Active Exploitation
7455.6%
Disclosure
2418.0%
General
1410.5%
Patch
139.8%
PoC
53.8%
Exploit
32.3%
Referenced assets156 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-2813
Disclosure6General1Patch2PoC4
2026-01-296
Disclosure2Exploit1General2Patch1
2026-01-306
Exploit1General2Patch2PoC1
2026-02-021
Disclosure1
2026-02-039
Active Exploitation5Disclosure3General1
2026-02-0442
Active Exploitation32Disclosure4General4Patch2
2026-02-0516
Active Exploitation10Disclosure2General1Patch3
2026-02-064
Active Exploitation2Patch2
2026-02-076
Active Exploitation4General1Patch1
2026-02-082
Active Exploitation1Disclosure1
2026-02-096
Active Exploitation5Disclosure1
2026-02-104
Active Exploitation3General1
2026-02-112
Active Exploitation2
2026-02-123
Active Exploitation2Disclosure1
2026-02-187
Active Exploitation4Disclosure1Exploit1General1
2026-02-191
Active Exploitation1
2026-02-242
Active Exploitation2
2026-02-251
Active Exploitation1
2026-03-051
Disclosure1
2026-03-261
Disclosure1
Full discourse20 posts
  • Horizon3 Attack Team@Horizon3Attack
    Disclosure

    Today we are disclosing the details of CVE-2025-40551, an unauth deserialization vuln leading to remote code execution affecting SolarWinds WebHelpDesk. Find the technical details, indicators of compromise, and proof-of-concept exploit in the blog. https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/

    Post summary

    The post discloses CVE‑2025‑40551, a deserialization flaw in SolarWinds WebHelpDesk that permits unauthenticated remote code execution, and points to a blog containing technical details and a proof‑of‑concept exploit.

    176326212328.8K
    12.1K followersView on X
  • Stephen Fewer@stephenfewer
    Exploit

    We now have a draft @metasploit module for the recent SolarWinds Web Help Desk vulns (CVE-2025-40536 + CVE-2025-40551) , based on the PoC by @Horizon3ai but with a gadget for loading native code modules to achieve RCE: https://github.com/rapid7/metasploit-framework/pull/20917

    Post summary

    A draft Metasploit module for SolarWinds Web Help Desk CVEs achieves remote code execution via native module loading, built on Horizon3ai's PoC.

    016069268.4K
    9.6K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 SolarWinds Web Help Desk flaw added to CISA KEV • CVE-2025-40551 (CVSS 9.8): unauthenticated RCE via deserialization • Fixed in WHD v2026.1 • Federal agencies must patch by February 6 🔗 Read → https://thehackernews.com/2026/02/cisa-adds-actively-exploited-solarwinds.html

    Post summary

    SolarWinds Web Help Desk CVE-2025-40551 has been added to the CISA KEV list, indicating active exploitation in the wild. A patch (WHD v2026.1) is available and federal agencies must apply it by February 6.

    32224967.0K
    1.0M followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ SolarWinds Web Help Desk RCE Hit by Multiple Critical Security Flaws; CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554 CVSS: All 9.8 CVEs Published: January 28th, 2026 CVE-2025-40551: SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. CVE-2025-40552: SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication. CVE-2025-40553: SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. CVE-2025-40554: SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

    Post summary

    Multiple critical CVEs (CVE-2025-40551‑54) have been disclosed for SolarWinds Web Help Desk, all scored 9.8, involving untrusted deserialization leading to RCE and authentication bypass, with no reported active exploitation or patch information presented.

    27125137.6K
    165.7K followersView on X
  • Defused@DefusedCyber
    PoC

    🍯 New FREE honeypot stream! 🚨 Multiple SolarWinds Web Help Desk vulns (incl. critical CVE-2025-40551) enable unauthed RCE - POC is public Track exploit activity in real time now 👉 https://console.defusedcyber.com/capabilities https://t.co/KREPCwxjvE

    Post summary

    The tweet announces SolarWinds Web Help Desk vulnerabilities, notably CVE‑2025‑40551, which allow unauthenticated RCE. A public proof‑of‑concept exists, and a honeypot stream is offered for tracking exploit activity.

    0712397.1K
    6.0K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    For the last few days, we have been sharing SolarWinds Help Desk CVE-2025-40551 RCE vulnerable IPs (version check based) - ~170 seen. This vuln is now on @CISACyber KEV. Data in Vulnerable HTTP reports: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=other_value&day=2026-02-02&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-40551%2B&data_set=count&scale=log&auto_update=on https://t.co/2Pa6CYymKF

    Post summary

    The post confirms that SolarWinds Help Desk CVE-2025-40551, an RCE vulnerability, is actively exploited in the wild (listed on CISA KEV) and 170 vulnerable IPs have been identified.

    16225411.1K
    21.6K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️ CISA has added 4 vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

    Post summary

    The tweet announces four CVEs added to CISA’s KEV catalog, giving brief technical details but no evidence of PoCs, active attacks, patches, or debunking claims.

    1401863.7K
    164.9K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2025-40551 (CVSS 9.8): SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. Search by vul.cve Filter 👉 vul.cve="CVE-2025-40551" ZoomEye Dork 👉 app="SolarWinds Web Help Desk" 25k+ exposed instances. ZoomEye Link: https://www.zoomeye.ai/searchResult?q=YXBwPSJTb2xhcldpbmRzIFdlYiBIZWxwIERlc2si&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260205 Refer: https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40551 #ZoomEye #NetSec #OSINT #CyberSecurity #SolarWinds #WebHelpDesk #Vulnerability #Infosec

    Post summary

    SolarWinds Web Help Desk is vulnerable to a deserialization flaw that allows unauthenticated remote code execution, with a CVSS score of 9.8. The advisory includes exposed instances but no evidence of active exploitation or a public PoC.

    0301772.0K
    11.9K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability https://x.com/DarkWebInformer/status/2016936977430695962

    Post summary

    The tweet announces SolarWinds Web Help Desk CVE‑2025‑40551 as a deserialization vulnerability but provides no PoC, exploit, patch, or exploitation evidence.

    031944.1K
    164.9K followersView on X
  • Horizon3.ai@Horizon3ai
    Patch

    🧵 Another SolarWinds Web Help Desk deserialization bug. Another patch bypass. We disclosed CVE-2025-40551 — an unauthenticated RCE in SolarWinds Web Help Desk. Here’s what matters 👇 https://t.co/CilJmdBsYG

    Post summary

    The tweet discloses a new unauthenticated RCE (CVE‑2025‑40551) in SolarWinds Web Help Desk and highlights that the existing patch can be bypassed.

    16450600
    2.6K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Active Exploitation

    CISA flags critical SolarWinds RCE flaw as exploited in attacks Tracked as CVE-2025-40551, this security flaw stems from an untrusted data deserialization weakness discovered and reported by http://Horizon3.ai security researcher Jimi Sebree, which can allow unauthenticated attackers to gain remote command execution on unpatched devices. https://nuel.ink/PJXqwo

    Post summary

    CISA has identified CVE-2025-40551 as being actively exploited in the wild, highlighting a critical untrusted data deserialization flaw that permits unauthenticated remote command execution on SolarWinds devices.

    111616.8K
    1.1K followersView on X
  • Dark Web Informer@DarkWebInformer
    General

    Advisories: https://nvd.nist.gov/vuln/detail/CVE-2025-40551 https://nvd.nist.gov/vuln/detail/CVE-2025-40552 https://nvd.nist.gov/vuln/detail/CVE-2025-40553 https://nvd.nist.gov/vuln/detail/CVE-2025-40554

    Post summary

    The text lists NVD links for four CVE entries without providing additional context or actionable details.

    010522.3K
    165.7K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/3追加) 🛡️No.1503 CVE-2025-40551 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability ============= CVSSスコア: 9.8 (Base) / SolarWinds CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:信頼できないデータのデシリアライゼーション (CWE-502 / SolarWinds) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからホストマシン上でコマンドを実行される恐れがあります。 https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40551 🛡️No.1504 CVE-2019-19006 Sangoma FreePBX Improper Authentication Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:不適切な認証 (CWE-287 / CISA-ADP) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、パスワード認証を回避し、FreePBX管理者が提供するサービスにアクセスされる恐れがあります。 https://iki.freepbx.org/display/FOP/2019-11-20%2BRemote%2BAdmin%2BAuthentication%2BBypass 🛡️No.1505 CVE-2025-64328 Sangoma FreePBX OS Command Injection Vulnerability ============= CVSSスコア: 8.6 (Base) / GitHub, Inc. CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 種別:OSコマンドインジェクション (CWE-78 / GitHub, Inc.) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、testconnection -> check_ssh_connect()関数を介してコマンドインジェクションをされる恐れがあります。この脆弱性を利用して、asteriskユーザーとしてシステムへのリモートアクセスを取得される可能性があります。 https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw 🛡️No.1506 CVE-2021-39935 GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability ============= CVSSスコア: 6.8 (Base) / GitHub, Inc. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N 種別:サーバサイドのリクエストフォージェリ (CWE-918 / GitHub, Inc.) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、CI Lint API を介してサーバーサイドリクエストを実行される恐れがあります。 https://about.gitlab.com/releases/2021/12/06/security-release-gitlab-14-5-2-released/ CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/03/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirms that four CVEs are actively exploited; the post supplies vulnerability details and links to vendor advisories for remediation.

    010604.0K
    42.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-40551 - critical 🚨 SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCE > SolarWinds Web Help Desk before version 2026.1 contains an insecure deserialization v... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-40551 @pdnuclei #NucleiTempl...

    Post summary

    CVE-2025-40551 is a critical vulnerability in SolarWinds Web Help Desk prior to version 2026.1, involving unauthenticated JNDI injection leading to remote code execution via insecure deserialization.

    01032273
    890 followersView on X
  • Hunt.io@Huntio
    Active Exploitation

    ⚠️ Internet-Facing WHD Servers Become Entry Points for Multistage Attacks https://www.darkreading.com/vulnerabilities-threats/solarwinds-whd-attacks-exposed-apps Attackers are actively targeting exposed SolarWinds Web Help Desk (WHD) instances, exploiting critical flaws like CVE-2025-40551. Microsoft and Huntress observed multistage intrusions starting from Internet-facing WHD servers, followed by PowerShell abuse, BITS downloads, and deployment of tools like Zoho, Cloudflare tunnels, and Velociraptor for persistence. Around 170 vulnerable instances are still publicly reachable, which keeps the attack surface wide open. #VulnerabilityManagement #SolarWinds #ThreatDetection

    Post summary

    The article reports that SolarWinds Web Help Desk servers are being actively exploited in the wild, with attackers using PowerShell, BITS, and various tools to establish persistence.

    02021528
    4.8K followersView on X
  • hiro_@papa_anniekey
    General

    KEV追加 CVE-2019-19006 Sangoma FreePBX CVE-2021-39935 GitLab Community and Enterprise Editions CVE-2025-40551 SolarWinds Web Help Desk CVE-2025-64328 Sangoma FreePBX

    Post summary

    A brief list of CVEs added to the KEV with associated products, without additional context or detail.

    00041681
    6.0K followersView on X
  • Soufiane@S0ufi4n3
    General

    https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/

    Post summary

    The URL points to a blog post about CVE-2025-40551, a deserialization vulnerability in SolarWinds Web Help Desk, but no further details such as PoC, exploit code, active exploitation, or patches are evident in the provided text.

    00023890
    14.3K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2025-40551: SolarWinds WebHelpDesk RCE Deep-Dive and Indicators of Compromise https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/

    Post summary

    CVE-2025-40551 exposes a remote code execution flaw in SolarWinds WebHelpDesk, and the linked article offers a deep technical dive and IOCs.

    00022642
    32.9K followersView on X
  • Autumn Good@autumn_good_35
    General

    Static Creds (CVE-2025-40537) Security Protection Bypass (CVE-2025-40536) Java Deserialization (CVE-2025-40551) CVE-2025-40551: Another Solarwinds Web Help Desk Deserialization Issue https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/

    Post summary

    The text lists several CVEs and provides a title and link for CVE-2025-40551, indicating it is a deserialization issue but offers no further detail or actionable information.

    101201.7K
    6.7K followersView on X
  • Misbar | مسبار@MisbarSec
    PoC

    🔹يوجد PoC لثغرة CVE-2025-40551 يعتمد على تجاوز تحقق CSRF وإرسال JSON-RPC لإنشاء JNDIConnectionPool لتنفيذ كود عن بعد. لتفاصيل: https://horizon3.ai/attack-research/vulnerabilities/cve-2025-40551/

    Post summary

    The message confirms a PoC for CVE‑2025‑40551, detailing a CSRF bypass and JSON‑RPC based remote code execution via JNDIConnectionPool, but does not report active attacks or patch availability.

    00040860
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsweb_help_desk---

Explore more