Horizon3 Attack Team[verified]@Horizon3AttackDisclosure
The post discloses CVE‑2025‑40551, a deserialization flaw in SolarWinds WebHelpDesk that permits unauthenticated remote code execution, and points to a blog containing technical details and a proof‑of‑concept exploit.
Stephen Fewer[verified]@stephenfewerExploit
A draft Metasploit module for SolarWinds Web Help Desk CVEs achieves remote code execution via native module loading, built on Horizon3ai's PoC.
ZoomEye[verified]@zoomeye_teamDisclosure
SolarWinds Web Help Desk is vulnerable to a deserialization flaw that allows unauthenticated remote code execution, with a CVSS score of 9.8. The advisory includes exposed instances but no evidence of active exploitation or a public PoC.
Horizon3.ai[verified]@Horizon3aiPatch
The tweet discloses a new unauthenticated RCE (CVE‑2025‑40551) in SolarWinds Web Help Desk and highlights that the existing patch can be bypassed.
Dr. John D. Johnson[verified]@johndjohnsonActive Exploitation
CISA has identified CVE-2025-40551 as being actively exploited in the wild, highlighting a critical untrusted data deserialization flaw that permits unauthenticated remote command execution on SolarWinds devices.
piyokango[verified]@piyokangoActive Exploitation
CISA confirms that four CVEs are actively exploited; the post supplies vulnerability details and links to vendor advisories for remediation.
Hunt.io[verified]@HuntioActive Exploitation
The article reports that SolarWinds Web Help Desk servers are being actively exploited in the wild, with attackers using PowerShell, BITS, and various tools to establish persistence.
Misbar | مسبار[verified]@MisbarSecPoC
The message confirms a PoC for CVE‑2025‑40551, detailing a CSRF bypass and JSON‑RPC based remote code execution via JNDIConnectionPool, but does not report active attacks or patch availability.