CVE-2025-26399
SolarWinds Web Help Desk: Deserialization of Untrusted Data
As of , CVE-2025-26399 in SolarWinds Web Help Desk is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch now.
- Exploited
- Yes: CISA listed it on 9 March 2026
- US federal deadline
- 12 March 20263 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- KnownCISA changed it from Unknown to Known on 4 August 2026.
- EPSS score
- 0.90Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- None foundNeither Metasploit nor Exploit-DB lists one.
- Fix
- Vendor advice: documentation.solarwinds.com and www.solarwinds.comLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA's required action
What the flaw is
SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.
CISA's description
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
The CVE record's description, from SolarWinds
- CVE published
- 23 September 2025
- Assigned by
- SolarWinds
- CVSS
- 9.8 Critical (CVSS 3.1, from the CNA)
- CWE-502
- Deserialization of Untrusted Data
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
- CISA changed its entry. Ransomware use: Unknown to Known.
Web Help Desk: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-40536Security Control Bypass | SolarWinds Web Help Desk | Patch this weekMetasploit module; EPSS 0.74 | 0.74 | ||
| CVE-2025-40551Deserialization of Untrusted Data | SolarWinds Web Help Desk | Patch this weekMetasploit module; EPSS 0.84 | 0.84 | ||
| CVE-2024-28987Hardcoded Credential | SolarWinds Web Help Desk | Patch this weekMetasploit module; EPSS 0.93 | 0.93 | ||
| CVE-2024-28986Deserialization of Untrusted Data | SolarWinds Web Help Desk | Patch this weekEPSS 0.85 | 0.85 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org