CVE-2025-40554Disclosure(solarwinds / web_help_desk)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch solarwinds web_help_desk systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1390

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_help_desk

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 7 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 15 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 8 mentions (2026-01-29); latest day: 1
  • 19 total mentions across 7 days

Affected systems

Vendors
Products
web_help_desk

Deep dive

Activity timeline19 mentions / 7d
02468Mentions · 2026-01-28: 5Mentions · 2026-01-29: 8Mentions · 2026-01-30: 2Mentions · 2026-02-02: 1Mentions · 2026-02-17: 1Mentions · 2026-02-27: 1Mentions · 2026-03-18: 1PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-02-02: 1PoC Mentioned / Linked · 2026-02-27: 1Exploit Tool / Code · 2026-01-29: 1Exploit Tool / Code · 2026-02-02: 1Active Exploitation · 2026-01-28: 2Patch / Workaround · 2026-01-28: 2Patch / Workaround · 2026-01-29: 4Patch / Workaround · 2026-01-30: 2Patch / Workaround · 2026-02-02: 1Technical Details · 2026-01-28: 5Technical Details · 2026-01-29: 6Technical Details · 2026-01-30: 2Technical Details · 2026-02-17: 1Technical Details · 2026-02-27: 101-2801-2901-3002-0202-1702-2703-18
Signal classification5 categories
Disclosure
842.1%
Patch
736.8%
General
210.5%
Active Exploitation
15.3%
PoC
15.3%
Referenced assets25 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-285
Active Exploitation1Disclosure3Patch1
2026-01-298
Disclosure3General1Patch3PoC1
2026-01-302
Patch2
2026-02-021
Patch1
2026-02-171
Disclosure1
2026-02-271
Disclosure1
2026-03-181
General1
Full discourse19 posts
  • Rishi@rxerium
    Disclosure

    🚨 2 critical authentication bypass and remote command execution vulnerabilities in Solarwinds WHD have been disclosed. Vulnerability detection scripts can be found below: CVE-2025-40552: https://github.com/rxerium/rxerium-templates/blob/main/2025/CVE-2025-40552.yaml CVE-2025-40554: https://github.com/rxerium/rxerium-templates/blob/main/2025/CVE-2025-40554.yaml At the time of writing there are no signs of active exploitation in the wild but it is strongly recommended that you patch as per Solarwind's security advisory: https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm

    Post summary

    The note announces two critical SolarWinds WHD vulnerabilities—authentication bypass and remote command execution—provides detection script links, confirms no current active exploitation, and urges patching via SolarWinds' advisory.

    218080514.8K
    3.1K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ SolarWinds Web Help Desk RCE Hit by Multiple Critical Security Flaws; CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554 CVSS: All 9.8 CVEs Published: January 28th, 2026 CVE-2025-40551: SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. CVE-2025-40552: SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication. CVE-2025-40553: SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. CVE-2025-40554: SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

    Post summary

    The post announces four critical CVEs in SolarWinds Web Help Desk, providing technical details such as RCE via deserialization and authentication bypass, but no evidence of active exploitation or mitigation.

    27125137.6K
    165.7K followersView on X
  • blackorbird@blackorbird
    Disclosure

    #Research Vulnerabilities in SolarWinds Web Help Desk CVE-2025-40552 - Authentication Bypass CVE-2025-40553 - Remote Code Execution via Deserialization CVE-2025-40554 - Authentication Bypass https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s/ https://t.co/bNRCyjHn5I

    Post summary

    The post announces three new SolarWinds Web Help Desk CVEs, lists basic technical details, and links to a blog post likely containing further information, but provides no evidence of exploitation, patches, or PoC code in the text.

    0712792.1K
    40.2K followersView on X
  • ET Labs@ET_Labs
    General

    19 new OPEN, 30 new PRO (19 + 11) BMC FootPrints (CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, CVE-2025-21760), LandUpdate808, Lumma Stealer, Proxy Service Domains, SolarWinds (CVE-2025-40554), UNK_VaporVibes, XWorm, ZPHP https://community.emergingthreats.net/t/ruleset-update-summary-2026-03-18-v11151/3236

    Post summary

    A ruleset update lists several newly identified CVE vulnerabilities associated with BMC FootPrints and SolarWinds but offers no further technical detail or exploit information.

    03032416
    5.7K followersView on X
  • Dark Web Informer@DarkWebInformer
    General

    Advisories: https://nvd.nist.gov/vuln/detail/CVE-2025-40551 https://nvd.nist.gov/vuln/detail/CVE-2025-40552 https://nvd.nist.gov/vuln/detail/CVE-2025-40553 https://nvd.nist.gov/vuln/detail/CVE-2025-40554

    Post summary

    The post consists solely of URLs to NVD advisory pages for CVE-2025-40551 through CVE-2025-40554, with no additional explanatory content.

    010522.3K
    165.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-40554 - critical 🚨 SolarWinds Web Help Desk - Authentication Bypass > SolarWinds Web Help Desk 12.8.8 HF1 and earlier contains an authentication bypass vul... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-40554 @pdnuclei #NucleiTemplates #cve

    Post summary

    A critical authentication bypass vulnerability (CVE-2025-40554) affects SolarWinds Web Help Desk versions 12.8.8 HF1 and earlier, with a link to further details.

    01031203
    888 followersView on X
  • d4rk_c0r3@d4rk_c0r3
    PoC

    CVE-2025-40554 – SolarWinds Web Help Desk Auth Bypass PoC https://github.com/imbas007/auth-bypass-CVE-2025-40554 https://t.co/UEkAByuyCf

    Post summary

    A Proof of Concept for an authentication bypass in SolarWinds Web Help Desk has been released, with the code available on GitHub.

    01021388
    147 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    SolarWinds has just announced four high-severity vulnerabilities in its Web Help Desk (WHD). CVE-2025-40551 & CVE-2025-40553 (Unauthenticated RCE) CVE-2025-40552 & CVE-2025-40554 (Auth Bypass) https://www.thehackerwire.com/solarwinds-patches-critical-rce-and-auth-bypass-flaws-in-web-help-desk/ https://t.co/j3F2jxa30N

    Post summary

    SolarWinds announced four high‑severity Web Help Desk flaws, including two unauthenticated RCE and two authentication bypass vulnerabilities.

    00011139
    113 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Today's Top Cybersecurity News – January 28, 2026 1. Active Exploitation of WinRAR Vulnerability CVE-2025-8088 by Threat Actors Google has identified active exploitation of a critical vulnerability in WinRAR, CVE-2025-8088, by nation-state and financially motivated groups. The flaw, patched in July 2025, is being used to gain initial access and deploy various payloads, posing significant risks to users who have not updated. Sources: Bleepingcomputer, Cvefeed, Cyberscoop, Feedburner, Mandiant, Securityweek https://thehackernews.com/2026/01/google-warns-of-active-exploitation-of.html 2. Critical Vulnerabilities Found in 100% of Enterprise AI Systems Amid Usage Surge Zscaler analysts discovered that all enterprise AI systems contain critical vulnerabilities, with 90% being compromised within 90 minutes. This highlights an urgent need for enhanced AI security measures as enterprise adoption of AI rises sharply. Source: Infosecurity-Magazine https://www.infosecurity-magazine.com/news/ai-security-threats-loom-zscaler/ 3. Critical FortiCloud SSO Vulnerability Exploited in the Wild Fortinet has confirmed an authentication bypass vulnerability in FortiCloud SSO, actively exploited as CVE-2026-24858. This poses significant risks to organizations using FortiOS and other Fortinet products. Sources: Bleepingcomputer, Cvefeed, Securityweek https://cybersecuritynews.com/fortinet-forticloud-sso-vulnerability/ 4. Critical Vulnerabilities in SolarWinds Web Help Desk Multiple critical vulnerabilities have been discovered in SolarWinds Web Help Desk, including authentication bypass and remote code execution flaws. These vulnerabilities could allow attackers to gain unauthorized access and execute arbitrary code on affected systems, posing significant risks to organizations using this software. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-40554 5. Critical RCE Vulnerability in n8n Workflow Platform A critical Remote Code Execution vulnerability has been discovered in the n8n workflow automation platform, potentially allowing attackers to execute arbitrary code remotely. This flaw poses significant security risks to systems using n8n, necessitating immediate attention and patching. Sources: Cvefeed https://securityonline.info/sandbox-shattered-critical-n8n-flaw-cvss-9-9-allows-remote-code-execution/ Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    Several critical vulnerabilities, including CVE‑2025‑8088 in WinRAR and CVE‑2026‑24858 in FortiCloud, are being actively exploited in the wild, with patches available for those that have been released.

    0001045
    54 followersView on X
  • 0x 64554D41@nkprorhah
    Patch

    CVE-2025-40554 disclosed: a security flaw enabling unauthorized actions under certain conditions. Vendors notified; patch guidance provided. Admins should review and update ASAP. POC: https://github.com/Skynoxk/CVE-2025-40554 #infosec #CVE https://t.co/ivdE0Hbr4K

    Post summary

    The tweet announces CVE-2025-40554, notes vendor patch guidance, and shares a PoC link, but does not describe active exploitation or detailed technical aspects.

    00000131
    1 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Fixes Critical Web Help Desk Bugs Enabling Auth Bypass and Remote Code Execution SolarWinds patched multiple WHD flaws (fixed in Web Help Desk 2026.1) including auth bypass (CVE-2025-40552, CVE-2025-40554) and unsafe deserialization RCE (CVE-2025-40553, CVE-2025-40551), plus a hardcoded-credentials issue (CVE-2025-40537), making exposed deployments urgent to upgrade due to historical rapid exploitation patterns. 🎯 Target: Global/Organizations using SolarWinds Web Help Desk #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.scworld.com/brief/solarwinds-patches-critical-vulnerabilities-in-web-help-desk-software

    Post summary

    SolarWinds has released patches for multiple critical Web Help Desk vulnerabilities—including auth bypass and remote code execution—and advises prompt upgrades to mitigate potential exploitation.

    00000101
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Fixes 4 Critical Web Help Desk Flaws Enabling Unauthenticated RCE & Auth Bypass SolarWinds patched six Web Help Desk vulnerabilities, including four critical (CVSS 9.8) issues that allow unauthenticated attackers to bypass authentication (CVE-2025-40552, CVE-2025-40554) and achieve RCE via unsafe deserialization (CVE-2025-40551), fixed in WHD 2026.1—making exposed instances a high-priority upgrade. 🎯 Target: Global/ITSM & Help Desk #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/187470/security/solarwinds-addressed-four-critical-web-help-desk-flaws.html

    Post summary

    SolarWinds fixed four critical Web Help Desk flaws (CVE‑2025‑40552, CVE‑2025‑40554, CVE‑2025‑40551) that allow unauthenticated authentication bypass and RCE; upgrading to WHD 2026.1 is recommended.

    0000070
    196 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #SolarWinds released Security Update to address an Authentication Bypass Vulnerability in SolarWinds Web Help Desk. Apply Update! #CVE-2025-40554 https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40554

    Post summary

    SolarWinds released a security update to address CVE‑2025‑40554, an authentication bypass flaw in SolarWinds Web Help Desk, and is urging users to apply the patch.

    00000130
    8.4K followersView on X
  • securityrss.ai@securityRSS
    Disclosure

    On January 28, 2026, SolarWinds disclosed multiple vulnerabilities in their Web Help Desk product, including four critical CVEs (CVE-2025-40551, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554) allowing unauthenticated remote code execution or authentic... https://www.rapid7.com/blog/post/etr-multiple-critical-solarwinds-web-help-desk-vulnerabilities-cve-2025-40551-40552-40553-40554

    Post summary

    SolarWinds announced four critical CVEs in Web Help Desk that allow unauthenticated remote code execution; the disclosure highlights the vulnerability severity.

    00000123
    74 followersView on X
  • Sami Laiho@samilaiho
    Patch

    SolarWinds Web Help Desk Authentication Bypass Vulnerability (CVE-2025-40554) Download PDF URL: https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40554 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8

    Post summary

    SolarWinds has disclosed a critical authentication bypass flaw in Web Help Desk (CVE‑2025‑40554) and issued an official fix; no active exploitation or PoC have been reported.

    00000430
    30.4K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    SolarWinds patches critical Web Help Desk vulnerabilities including authentication bypass (CVE-2025-40552, CVE-2025-40554) and RCE via untrusted deserialization (CVE-2025-40553). Hardcoded credentials flaw also fixed. #SolarWinds #RCEFlaws #USA https://ift.tt/h8BzIXp

    Post summary

    SolarWinds has released patches for three Web Help Desk CVEs—authentication bypass and RCE via untrusted deserialization—alongside a fix for hardcoded credentials.

    00000172
    3.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『if exploited, could allow an attacker to invoke specific actions within Web Help Desk.』 SolarWinds Web Help Desk Authentication Bypass Vulnerability (CVE-2025-40554) https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40554

    Post summary

    The tweet announces CVE‑2025‑40554, an authentication bypass in SolarWinds Web Help Desk that could let an attacker perform specific actions, but it does not mention exploits, patches, or active attacks.

    00000422
    6.7K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SolarWinds Patches Critical Web Help Desk Auth-Bypass + Remote Command Execution Flaws SolarWinds fixed critical unauthenticated auth-bypass bugs (CVE-2025-40552, CVE-2025-40554) and remote command execution issues (CVE-2025-40553, CVE-2025-40551) in Web Help Desk, including deserialization-based RCE that can let attackers run commands on vulnerable servers. Upgrade to Web Help Desk 2026.1 immediately, as WHD bugs have a track record of rapid real-world exploitation. 🎯 Target: Global/SolarWinds Web Help Desk Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.bleepingcomputer.com/news/security/solarwinds-warns-of-critical-web-help-desk-rce-auth-bypass-flaws/

    Post summary

    The notice announces that SolarWinds has released a patch for critical auth-bypass and RCE flaws in Web Help Desk, emphasizing the need to upgrade immediately due to rapid real-world exploitation of these vulnerabilities.

    0000079
    196 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-40554 SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions … https://www.cve.org/CVERecord?id=CVE-2025-40554

    Post summary

    SolarWinds Web Help Desk (CVE-2025-40554) is disclosed as having an authentication bypass vulnerability that could let attackers invoke specific actions.

    00000230
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsweb_help_desk---

Explore more