CVE-2025-40553Disclosure(solarwinds / web_help_desk)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch solarwinds web_help_desk systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_help_desk

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 18 mentions across 8 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 17 signals
  • Disclosure: 9 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 6 mentions (2026-01-28); latest day: 1
  • 18 total mentions across 8 days

Affected systems

Vendors
Products
web_help_desk

Deep dive

Activity timeline18 mentions / 8d
02356Mentions · 2026-01-28: 6Mentions · 2026-01-29: 6Mentions · 2026-01-30: 1Mentions · 2026-02-03: 1Mentions · 2026-02-18: 1Mentions · 2026-02-26: 1Mentions · 2026-02-27: 1Mentions · 2026-03-04: 1PoC Mentioned / Linked · 2026-02-26: 1Exploit Tool / Code · 2026-02-26: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-29: 3Patch / Workaround · 2026-01-30: 1Technical Details · 2026-01-28: 6Technical Details · 2026-01-29: 5Technical Details · 2026-01-30: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-04: 101-2801-2901-3002-0302-1802-2602-2703-04
Signal classification5 categories
Disclosure
950.0%
Patch
527.8%
General
211.1%
Exploit
15.6%
Active Exploitation
15.6%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-01-286
Disclosure5Patch1
2026-01-296
Disclosure2General1Patch3
2026-01-301
Patch1
2026-02-031
Disclosure1
2026-02-181
General1
2026-02-261
Exploit1
2026-02-271
Disclosure1
2026-03-041
Active Exploitation1
Full discourse18 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ SolarWinds Web Help Desk RCE Hit by Multiple Critical Security Flaws; CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554 CVSS: All 9.8 CVEs Published: January 28th, 2026 CVE-2025-40551: SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. CVE-2025-40552: SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication. CVE-2025-40553: SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. CVE-2025-40554: SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

    Post summary

    The post announces four high‑severity CVEs in SolarWinds Web Help Desk, detailing untrusted data deserialization and authentication bypass vulnerabilities that enable remote code execution or unauthorized actions.

    27125137.6K
    165.7K followersView on X
  • blackorbird@blackorbird
    Disclosure

    #Research Vulnerabilities in SolarWinds Web Help Desk CVE-2025-40552 - Authentication Bypass CVE-2025-40553 - Remote Code Execution via Deserialization CVE-2025-40554 - Authentication Bypass https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s/ https://t.co/bNRCyjHn5I

    Post summary

    The post announces three new SolarWinds Web Help Desk CVEs—two authentication bypasses and one RCE via deserialization—and links to a blog that presumably details the exploit chain.

    0712792.1K
    40.2K followersView on X
  • Dark Web Informer@DarkWebInformer
    General

    Advisories: https://nvd.nist.gov/vuln/detail/CVE-2025-40551 https://nvd.nist.gov/vuln/detail/CVE-2025-40552 https://nvd.nist.gov/vuln/detail/CVE-2025-40553 https://nvd.nist.gov/vuln/detail/CVE-2025-40554

    Post summary

    The post merely lists links to NVD advisory pages for four CVEs, providing no additional details on exploitation, patches, or vulnerability specifics.

    010522.3K
    165.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    SolarWinds has just announced four high-severity vulnerabilities in its Web Help Desk (WHD). CVE-2025-40551 & CVE-2025-40553 (Unauthenticated RCE) CVE-2025-40552 & CVE-2025-40554 (Auth Bypass) https://www.thehackerwire.com/solarwinds-patches-critical-rce-and-auth-bypass-flaws-in-web-help-desk/ https://t.co/j3F2jxa30N

    Post summary

    SolarWinds has announced four high‑severity Web Help Desk vulnerabilities, including unauthenticated remote code execution and authentication bypass defects.

    00011139
    113 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: 6 high to critical vulnerabilities in #SolarWinds Help Desk. CVE-2025-40551 and CVE-2025-40553 (CVSS: 9.8) could be exploited by remote attackers to achieve remote code execution #RCE! #Patch #Patch #Patch

    Post summary

    The message warns about newly disclosed high‑severity vulnerabilities in SolarWinds Help Desk, highlighting CVSS scores and potential remote code execution, but offers no PoC, exploit code, or patch details.

    02000205
    7.2K followersView on X
  • transilienceai@transilienceai
    General

    Impact: Provides a foothold for chaining with deserialization flaws (e.g., CVE-2025-40551, CVE-2025-40553) to achieve unauthenticated RCE. Attackers can execute arbitrary commands, spawn PowerShell for payload downloads via BITS, disable defenses like Windows Defender/Firewall, and enable persistence with tools like Cloudflared or Zoho ManageEngine components. #ThreatHunting

    Post summary

    The text explains how CVE-2025-40551 and CVE-2025-40553 can be chained to achieve unauthenticated RCE, outlining attacker actions but providing no evidence of active exploitation, PoC, or patch.

    1000051
    313 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-40553 SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an… https://www.cve.org/CVERecord?id=CVE-2025-40553

    Post summary

    SolarWinds Web Help Desk has an untrusted deserialization flaw that could lead to RCE; the text provides the vulnerability details but no patches, PoC, or exploit information.

    00010258
    56.5K followersView on X
  • RagingCISO@CisoRaging77913
    Active Exploitation

    CVE-2025-40553/40554: SolarWinds WHD—unauth deserialization RCE + auth bypass + hardcoded "client" creds. OWASP Top 10 bingo. After 2020's supply chain fiasco, still shipping intern-level mistakes. Domain compromise observed ITW. Contemporary art of insecurity.

    Post summary

    SolarWinds WHD is vulnerable to unauthenticated deserialization RCE and authentication bypass, with hardcoded credentials; domain compromise has been observed in the wild.

    0000079
    5 followersView on X
  • BimBox@hdH4dg8
    Exploit

    https://github.com/watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553?ref=labs.watchtowr.com

    Post summary

    The GitHub repository hosts exploit code for CVE-2025-40552 and CVE-2025-40553 against SolarWinds WebHelpDesk, providing a functional demonstration but no evidence of active exploitation or patch information.

    0000097
    47 followersView on X
  • RagingCISO@CisoRaging77913
    Disclosure

    CVE-2025-40553: SolarWinds WHD—unauth RCE via Java gadget chains. CVSS 9.8, 90% unpatched. Four critical CVEs in one product. SolarWinds gave us supply chain compromise in 2020—now they're targeting your helpdesk. CWE-502, entirely predictable. Legacy? No, negligence.

    Post summary

    The text announces CVE‑2025‑40553, a severe unauthenticated RCE in SolarWinds WHD, detailing its CVSS score, exploitation vector, and lack of patches, without evidence of PoC, active exploitation, or mitigation steps.

    0000070
    4 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Fixes Critical Web Help Desk Bugs Enabling Auth Bypass and Remote Code Execution SolarWinds patched multiple WHD flaws (fixed in Web Help Desk 2026.1) including auth bypass (CVE-2025-40552, CVE-2025-40554) and unsafe deserialization RCE (CVE-2025-40553, CVE-2025-40551), plus a hardcoded-credentials issue (CVE-2025-40537), making exposed deployments urgent to upgrade due to historical rapid exploitation patterns. 🎯 Target: Global/Organizations using SolarWinds Web Help Desk #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/solarwinds-patches-critical-vulnerabilities-in-web-help-desk-software

    Post summary

    SolarWinds released a patch for multiple critical Web Help Desk vulnerabilities—including auth bypass, unsafe deserialization RCE, and hardcoded credentials—urging organizations to upgrade to version 2026.1.

    00000101
    196 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #SolarWinds released Security Update to address a Deserialization of Untrusted Data Vulnerability in SolarWinds Web Help Desk. Apply Update! #CVE-2025-40553 https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40553

    Post summary

    The statement informs users that SolarWinds has released a security update for CVE‑2025‑40553 to fix a deserialization vulnerability in SolarWinds Web Help Desk, urging them to apply the patch.

    00000121
    8.4K followersView on X
  • securityrss.ai@securityRSS
    Disclosure

    On January 28, 2026, SolarWinds disclosed multiple vulnerabilities in their Web Help Desk product, including four critical CVEs (CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554) allowing unauthenticated remote code execution or authentic... https://www.rapid7.com/blog/post/etr-multiple-critical-solarwinds-web-help-desk-vulnerabilities-cve-2025-40551-40552-40553-40554

    Post summary

    SolarWinds disclosed four critical CVEs in its Web Help Desk product that enable unauthenticated remote code execution; the post provides technical details but no patches, PoCs, or evidence of active exploitation.

    00000123
    74 followersView on X
  • Sami Laiho@samilaiho
    Patch

    SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-40553) URL: https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40553 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8

    Post summary

    SolarWinds has released an advisory for CVE-2025-40553, highlighting a critical remote code execution flaw tied to deserialization of untrusted data, with an official vendor fix already available.

    00000352
    30.4K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    SolarWinds patches critical Web Help Desk vulnerabilities including authentication bypass (CVE-2025-40552, CVE-2025-40554) and RCE via untrusted deserialization (CVE-2025-40553). Hardcoded credentials flaw also fixed. #SolarWinds #RCEFlaws #USA https://ift.tt/h8BzIXp

    Post summary

    SolarWinds has released patches for Web Help Desk to fix authentication bypass and remote code execution vulnerabilities (CVE‑2025‑40552, 40553, 40554), including removal of hard‑coded credentials.

    00000172
    3.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『This could be exploited without authentication.』 SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-40553) https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40553

    Post summary

    The post announces CVE-2025-40553, a SolarWinds Web Help Desk deserialization vulnerability that allows unauthenticated remote code execution. It provides the vulnerability type but offers no PoC, exploit, or mitigation details.

    00000380
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-40553 Unauthenticated Remote Code Execution in SolarWinds Web Help Desk via Deserialization https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-40553

    Post summary

    A new unauthenticated RCE vulnerability (deserialization) affecting SolarWinds Web Help Desk has been documented under CVE‑2025‑40553.

    0000035
    4.0K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Patches Critical Web Help Desk Auth-Bypass + Remote Command Execution Flaws SolarWinds fixed critical unauthenticated auth-bypass bugs (CVE-2025-40552, CVE-2025-40554) and remote command execution issues (CVE-2025-40553, CVE-2025-40551) in Web Help Desk, including deserialization-based RCE that can let attackers run commands on vulnerable servers. Upgrade to Web Help Desk 2026.1 immediately, as WHD bugs have a track record of rapid real-world exploitation. 🎯 Target: Global/SolarWinds Web Help Desk Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.bleepingcomputer.com/news/security/solarwinds-warns-of-critical-web-help-desk-rce-auth-bypass-flaws/

    Post summary

    SolarWinds has released patches for critical auth‑bypass and remote command execution flaws in Web Help Desk; users should promptly upgrade to version 2026.1 to prevent exploitation.

    0000079
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsweb_help_desk---

Explore more