CVE-2025-40551
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 February 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 83.62% probability · 100th percentile
- CISA KEV
- Listed 3 February 2026 · due 6 February 2026
- Weakness
- CWE-502
- Affected
- solarwinds/web help desk
- Source
- psirt@solarwinds.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40551 ; https://nvd.nist.gov/vuln/detail/CVE-2025-40551
References
- https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmRelease Notes
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40551Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40551US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.