Rishi[verified]@rxeriumDisclosure
SolarWinds WHD vulnerabilities CVE-2025-40552 and CVE-2025-40554 are disclosed with detection script links; patching is advised, but no active exploitation is reported.
blackorbird[verified]@blackorbirdDisclosure
Research post announces three CVEs affecting SolarWinds Web Help Desk, detailing authentication bypass and RCE via deserialization, with a linked article for further information.
ThreatSynop[verified]@ThreatSynopActive Exploitation
SolarWinds Web Help Desk instances are actively exploited for a high‑severity unauthenticated RCE (CVE‑2025‑40551). Immediate patching is required, with SolarWinds already released the fix in version 2026.1.
ThreatSynop[verified]@ThreatSynopActive Exploitation
SolarWinds Web Help Desk is being actively exploited via unauthenticated deserialization RCE (CVE‑2025‑40551) and related auth‑bypass issues; immediate patching to WHD 2026.1 is urged.
ThreatSynop[verified]@ThreatSynopPatch
SolarWinds released a patch in Web Help Desk 2026.1 that addresses multiple critical CVEs—including auth bypass, unsafe deserialization RCE, and hardcoded credentials—and urges organizations to upgrade due to past rapid exploitation patterns.
ThreatSynop[verified]@ThreatSynopPatch
SolarWinds issued a patch (WHD 2026.1) addressing four critical Web Help Desk flaws (CVE‑2025‑40551, 40552, 40554) that allow unauthenticated RCE and auth bypass. No exploits or active use are reported, only the vendor advisory.
Sami Laiho[verified]@samilaihoPatch
SolarWinds released a critical authentication bypass fix for Web Help Desk (CVE‑2025‑40552) with a high CVSS score; no PoC or active exploitation reported.
Machina Record[verified]@MachinaRecordPatch
The message announces that several major SolarWinds Web Help Desk vulnerabilities (CVE-2025-40552, 40553, etc.) have been fixed, indicating the release of relevant patches.