Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories

February 6, 2026

Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps

February 6, 2026

SolarWinds Web Help Desk Vulnerability Actively Exploited

February 6, 2026
Facebook X (Twitter) Instagram
Friday, February 6
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»SolarWinds Web Help Desk Vulnerability Actively Exploited
News

SolarWinds Web Help Desk Vulnerability Actively Exploited

Team-CWDBy Team-CWDFebruary 6, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A US security agency has warned SolarWinds Web Help Desk users that a remote code execution (RCE) vulnerability patched by the vendor last week is being actively exploited.

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-40551 to its Known Exploited Vulnerabilities (KEV) Catalog yesterday, giving federal civilian agencies until Friday to patch it.

The CVE has a CVSS score of 9.8 as it could allow unauthenticated adversaries to gain admin-level access to help-desk systems in low complexity attacks.

It’s described by CISA as a “deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine.”

Read more on SolarWinds CVEs: SolarWinds Urges Upgrade After Revealing Critical RCE Bug.

The three-day deadline mandated by CISA hints at the seriousness of potential exploitation. The popular IT ticketing software is used across government, but also in the private sector, especially in education and healthcare.

Although CISA’s KEV applies only to federal agencies, enterprises should broadly follow the same advice in order to minimize their attack surface.

Four Critical Vulnerabilities Identified 

Discovered by Jimi Sebree of Horizon3.ai, CVE-2025-40551 is one of four critical vulnerabilities found in SolarWinds Web Help Desk and fixed by the vendor in an update on January 28.

The remaining three were found by Piotr Bazydlo from watchTowr. CVE-2025-40553 is given the exact same description as CVE-2025-40551: a deserialization of untrusted data RCE vulnerability.

CVE-2025-40552 is an authentication bypass vulnerability which could allow an attacker to “execute actions and methods that should be protected by authentication.” CVE-2025-40554 is also an authentication bypass vulnerability, but one which, if exploited, “could allow an attacker to invoke specific actions within Web Help Desk.”

All four are assigned CVSS scores of 9.8, although only CVE-2025-40551 appears to be under active exploitation at the time of writing.

Attackers could chain CVE-2025-40552 or CVE-2025-40554 with CVE-2025-40551 or CVE-2025-40553 to gain complete control of targeted systems for lateral movement, data theft and ransomware.

Customers are urged to update vulnerable servers to Web Help Desk 2026.1 as soon as possible according to SolarWinds’ instructions.

Image credit: Ascannio / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026
Next Article Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps
Team-CWD
  • Website

Related Posts

News

New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories

February 6, 2026
News

Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps

February 6, 2026
News

3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026

February 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

It’s all fun and games until someone gets hacked

September 26, 2025

Drowning in spam or scam emails lately? Here’s why

January 27, 2026

Chronology of a Skype attack

February 5, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.