CVE-2025-40552Patch(solarwinds / web_help_desk)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch solarwinds web_help_desk systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1390

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_help_desk

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 22 mentions across 8 observed days

What's happening

  • Active exploitation reported across 3 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 18 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 8 mentions (2026-01-29); latest day: 1
  • 22 total mentions across 8 days

Affected systems

Vendors
Products
web_help_desk

Deep dive

Activity timeline22 mentions / 8d
02468Mentions · 2026-01-28: 6Mentions · 2026-01-29: 8Mentions · 2026-01-30: 2Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1Mentions · 2026-02-26: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-02-26: 1PoC Mentioned / Linked · 2026-02-27: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-02-04: 1Active Exploitation · 2026-02-05: 1Patch / Workaround · 2026-01-28: 4Patch / Workaround · 2026-01-29: 5Patch / Workaround · 2026-01-30: 2Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-01-28: 6Technical Details · 2026-01-29: 6Technical Details · 2026-01-30: 2Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 101-2801-2901-3002-0402-0502-2602-2702-28
Signal classification4 categories
Patch
1045.5%
Disclosure
731.8%
General
313.6%
Active Exploitation
29.1%
Referenced assets24 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-286
Disclosure2Patch4
2026-01-298
Disclosure3General1Patch4
2026-01-302
Patch2
2026-02-041
Active Exploitation1
2026-02-051
Active Exploitation1
2026-02-262
Disclosure1General1
2026-02-271
Disclosure1
2026-02-281
General1
Full discourse20 posts
  • Rishi@rxerium
    Disclosure

    🚨 2 critical authentication bypass and remote command execution vulnerabilities in Solarwinds WHD have been disclosed. Vulnerability detection scripts can be found below: CVE-2025-40552: https://github.com/rxerium/rxerium-templates/blob/main/2025/CVE-2025-40552.yaml CVE-2025-40554: https://github.com/rxerium/rxerium-templates/blob/main/2025/CVE-2025-40554.yaml At the time of writing there are no signs of active exploitation in the wild but it is strongly recommended that you patch as per Solarwind's security advisory: https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm

    Post summary

    SolarWinds WHD vulnerabilities CVE-2025-40552 and CVE-2025-40554 are disclosed with detection script links; patching is advised, but no active exploitation is reported.

    218080514.8K
    3.1K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ SolarWinds Web Help Desk RCE Hit by Multiple Critical Security Flaws; CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554 CVSS: All 9.8 CVEs Published: January 28th, 2026 CVE-2025-40551: SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. CVE-2025-40552: SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication. CVE-2025-40553: SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. CVE-2025-40554: SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

    Post summary

    SolarWinds Web Help Desk is affected by four critical CVEs (CVE‑2025‑40551‑40554) with CVSS 9.8, offering remote code execution via deserialization and authentication bypass vulnerabilities.

    27125137.6K
    165.7K followersView on X
  • blackorbird@blackorbird
    Disclosure

    #Research Vulnerabilities in SolarWinds Web Help Desk CVE-2025-40552 - Authentication Bypass CVE-2025-40553 - Remote Code Execution via Deserialization CVE-2025-40554 - Authentication Bypass https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s/ https://t.co/bNRCyjHn5I

    Post summary

    Research post announces three CVEs affecting SolarWinds Web Help Desk, detailing authentication bypass and RCE via deserialization, with a linked article for further information.

    0712792.1K
    40.2K followersView on X
  • Dark Web Informer@DarkWebInformer
    General

    Advisories: https://nvd.nist.gov/vuln/detail/CVE-2025-40551 https://nvd.nist.gov/vuln/detail/CVE-2025-40552 https://nvd.nist.gov/vuln/detail/CVE-2025-40553 https://nvd.nist.gov/vuln/detail/CVE-2025-40554

    Post summary

    The post simply lists NVD links for four CVEs, providing no additional context on exploitation, patches or technical details.

    010522.3K
    165.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-40552 - critical 🚨 SolarWinds Web Help Desk - Authentication Bypass > SolarWinds Web Help Desk contains an authentication bypass vulnerability caused by im... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-40552 @pdnuclei #NucleiTemplates #cve

    Post summary

    SolarWinds Web Help Desk has a critical authentication bypass vulnerability (CVE-2025-40552) disclosed, with a link to a ProjectDiscovery library entry for further details.

    00052229
    890 followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    SolarWinds has just announced four high-severity vulnerabilities in its Web Help Desk (WHD). CVE-2025-40551 & CVE-2025-40553 (Unauthenticated RCE) CVE-2025-40552 & CVE-2025-40554 (Auth Bypass) https://www.thehackerwire.com/solarwinds-patches-critical-rce-and-auth-bypass-flaws-in-web-help-desk/ https://t.co/j3F2jxa30N

    Post summary

    SolarWinds announced four high‑severity CVEs (two unauthenticated RCEs and two auth‑bypass flaws) in its Web Help Desk and provided patch information.

    00011139
    113 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-35202 2 - CVE-2019-12735 3 - CVE-2025-40552 4 - CVE-2026-21253 5 - CVE-2026-28515 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVE identifiers without providing additional technical, exploit, or remediation information.

    00000342
    1.7K followersView on X
  • BimBox@hdH4dg8
    General

    https://github.com/watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553?ref=labs.watchtowr.com

    Post summary

    The text provides only a link to a GitHub repository referencing CVE-2025-40552 and CVE-2025-40553, with no additional details about PoC, exploit, patch, or technical specifics.

    0000097
    47 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 170+ SolarWinds Web Help Desk Servers Exposed to Actively Exploited Unauth RCE (CVE-2025-40551) Over 170 internet-facing SolarWinds Web Help Desk instances are still vulnerable to an unauthenticated insecure-deserialization RCE (CVSS 9.8) in AjaxProxy, now confirmed exploited and added to CISA’s KEV with a Feb 6, 2026 remediation deadline for federal agencies. SolarWinds fixed it in Web Help Desk 2026.1 alongside three other critical issues (CVE-2025-40552/40553/40554), making immediate patching and external exposure reduction urgent. 🎯 Target: Global/IT Service Desk & Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/solarwinds-help-desk-installations-vulnerable/

    Post summary

    SolarWinds Web Help Desk instances are actively exploited for a high‑severity unauthenticated RCE (CVE‑2025‑40551). Immediate patching is required, with SolarWinds already released the fix in version 2026.1.

    0000056
    192 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 SolarWinds Web Help Desk flaws under active exploitation; CISA urges immediate patching CISA flagged SolarWinds Web Help Desk as actively exploited, centered on critical unauthenticated deserialization RCE (CVE-2025-40551) and related critical auth-bypass/RCE-adjacent issues (CVE-2025-40552/40553/40554), enabling full host takeover of exposed helpdesk servers. Organizations should upgrade to WHD 2026.1 immediately and treat any internet-facing WHD instance as a high-priority IR/hunting candidate. 🎯 Target: Global/IT Service Management #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.infosecurity-magazine.com/news/solarwinds-web-help-desk/

    Post summary

    SolarWinds Web Help Desk is being actively exploited via unauthenticated deserialization RCE (CVE‑2025‑40551) and related auth‑bypass issues; immediate patching to WHD 2026.1 is urged.

    0000063
    192 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Fixes Critical Web Help Desk Bugs Enabling Auth Bypass and Remote Code Execution SolarWinds patched multiple WHD flaws (fixed in Web Help Desk 2026.1) including auth bypass (CVE-2025-40552, CVE-2025-40554) and unsafe deserialization RCE (CVE-2025-40553, CVE-2025-40551), plus a hardcoded-credentials issue (CVE-2025-40537), making exposed deployments urgent to upgrade due to historical rapid exploitation patterns. 🎯 Target: Global/Organizations using SolarWinds Web Help Desk #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/solarwinds-patches-critical-vulnerabilities-in-web-help-desk-software

    Post summary

    SolarWinds released a patch in Web Help Desk 2026.1 that addresses multiple critical CVEs—including auth bypass, unsafe deserialization RCE, and hardcoded credentials—and urges organizations to upgrade due to past rapid exploitation patterns.

    00000101
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Fixes 4 Critical Web Help Desk Flaws Enabling Unauthenticated RCE & Auth Bypass SolarWinds patched six Web Help Desk vulnerabilities, including four critical (CVSS 9.8) issues that allow unauthenticated attackers to bypass authentication (CVE-2025-40552, CVE-2025-40554) and achieve RCE via unsafe deserialization (CVE-2025-40551), fixed in WHD 2026.1—making exposed instances a high-priority upgrade. 🎯 Target: Global/ITSM & Help Desk #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/187470/security/solarwinds-addressed-four-critical-web-help-desk-flaws.html

    Post summary

    SolarWinds issued a patch (WHD 2026.1) addressing four critical Web Help Desk flaws (CVE‑2025‑40551, 40552, 40554) that allow unauthenticated RCE and auth bypass. No exploits or active use are reported, only the vendor advisory.

    0000070
    196 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #SolarWinds released Security Update to address an Authentication Bypass Vulnerability in SolarWinds Web Help Desk. Apply Update! #CVE-2025-40552 https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40552

    Post summary

    SolarWinds is issuing a security update for CVE-2025-40552, an authentication bypass vulnerability, and urges users to apply the patch.

    00000120
    8.4K followersView on X
  • securityrss.ai@securityRSS
    Disclosure

    On January 28, 2026, SolarWinds disclosed multiple vulnerabilities in their Web Help Desk product, including four critical CVEs (CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554) allowing unauthenticated remote code execution or authentic... https://www.rapid7.com/blog/post/etr-multiple-critical-solarwinds-web-help-desk-vulnerabilities-cve-2025-40551-40552-40553-40554

    Post summary

    SolarWinds disclosed four critical CVEs that allow unauthenticated remote code execution in its Web Help Desk, without mentioning PoCs, exploitation, or patches.

    00000123
    74 followersView on X
  • Sami Laiho@samilaiho
    Patch

    SolarWinds Web Help Desk Authentication Bypass Vulnerability (CVE-2025-40552) URL: https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40552 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8

    Post summary

    SolarWinds released a critical authentication bypass fix for Web Help Desk (CVE‑2025‑40552) with a high CVSS score; no PoC or active exploitation reported.

    00000465
    30.4K followersView on X
  • Machina Record@MachinaRecord
    Patch

    🩹SolarWinds、Web Help Deskにおける重大な脆弱性を複数修正(CVE-2025-40552、CVE-2025-40553他) 🔑WhatsApp、高リスクユーザーのアカウントセキュリティを強化 〜サイバーアラート1月29日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/43668/

    Post summary

    The message announces that several major SolarWinds Web Help Desk vulnerabilities (CVE-2025-40552, 40553, etc.) have been fixed, indicating the release of relevant patches.

    00000181
    1.2K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    SolarWinds patches critical Web Help Desk vulnerabilities including authentication bypass (CVE-2025-40552, CVE-2025-40554) and RCE via untrusted deserialization (CVE-2025-40553). Hardcoded credentials flaw also fixed. #SolarWinds #RCEFlaws #USA https://ift.tt/h8BzIXp

    Post summary

    SolarWinds released patches for three critical Web Help Desk CVEs—addressing authentication bypass, untrusted deserialization leading to RCE, and hardcoded credentials—effectively mitigating the identified weaknesses.

    00000172
    3.6K followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Patch

    CVE-2025-40552 i SolarWinds Web Help Desk tillåter autentisering bypass, vilket kan leda till allvarliga säkerhetsrisker. Åtgärda omedelbart genom att uppdatera till senaste versionen. #säkerhet #cybersäkerhet #CVE

    Post summary

    A security advisory discloses that CVE‑2025‑40552 in SolarWinds Web Help Desk permits an authentication bypass, poses serious risks, and advises users to immediately update to the latest version.

    0000072
    7 followersView on X
  • RedLegg@RedLegg
    Patch

    Security Bulletin: SolarWinds WHD (CVE-2025-40552, CVSS 9.8) allows authentication bypass via improper access controls. Upgrade to 2026.1 now. #ThreatIntel #RedLeggCTI https://hubs.li/Q040PPfJ0

    Post summary

    SolarWinds WHD has a high‑severity authentication bypass flaw (CVE‑2025‑40552, CVSS 9.8) that requires users to upgrade to version 2026.1 to mitigate the vulnerability.

    0000091
    2.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-40552: SolarWinds Web Help Desk Authent... Authentication bypass in SolarWinds Web Help Desk enables unauthenticated attackers to execute privileged actions remot... https://zerodaysignal.com/vulnerability/CVE-2025-40552 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The snippet announces CVE‑2025‑40552 as an authentication bypass in SolarWinds Web Help Desk that allows unauthenticated remote privilege escalation, with no exploit, patch, or active exploitation details provided.

    0000065
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsweb_help_desk---

Explore more