Skip to main content

Web Help Desk vulnerabilities

3 published alerts for SolarWinds Web Help Desk.

Actively exploited (KEV)Ransomware

CVE-2025-26399

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds Web Help Desk is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-26399). SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine. CISA remediation due date: 2026-03-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-40536

SolarWinds Web Help Desk Security Control Bypass Vulnerability

SolarWinds Web Help Desk is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-40536). SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality. CISA remediation due date: 2026-02-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-40551

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds Web Help Desk is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-40551). SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. CISA remediation due date: 2026-02-06. If you need help checking exposure, call (864) 335-9223.