CISA has flagged a critical SolarWinds Web Help Desk vulnerability as actively exploited in attacks and ordered federal agencies to patch their systems within three days. Tracked as CVE-2025-40551, this security flaw stems from an untrusted data deserialization weakness discovered and reported by Horizon3.ai security researcher Jimi Sebree, which can allow unauthenticated attackers to gain remote command execution on unpatched devices. "SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution which would allow an attacker to run commands on the host machine," the company explained on January 28 when it released Web Help Desk 2026.1 to patch the vulnerability. The same day, SolarWinds also patched a high-severity hardcoded-credentials vulnerability (CVE-2025-40537) discovered by Sebree and two authentication-bypass security flaws (CVE-2025-40552 and CVE-2025-40554) reported by watchTowr's Piotr Bazydlo, all of them remotely exploitable. On Tuesday, CISA added CVE-2025-40551 to its catalog of flaws exploited in the wild and gave Federal Civilian Executive Branch (FCEB) agencies three days to secure their systems, as mandated by the Binding Operational Directive (BOD) 22-01, issued in November 2021. Although BOD 22-01 targets only federal agencies, CISA encouraged all network defenders, including those in the private sector, to patch their devices against ongoing CVE-2025-40551 attacks as so...
CISA flags critical SolarWinds RCE flaw as exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Feb 3, 2026
·Updated
Affected Software
1 affected component
SolarWinds Web Help Desk>=2026.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in SolarWinds Web Help Desk that is being actively exploited in attacks.
2
What security implications are discussed?
The article highlights the urgency for federal agencies to patch the vulnerability to prevent potential remote code execution attacks.
3
What is the CVE identifier for the SolarWinds vulnerability?
The vulnerability is tracked as CVE-2025-40551.
4
Which specific product is affected by this vulnerability?
The affected product is SolarWinds Web Help Desk.
5
What is the minimum version of the affected software?
The vulnerability affects SolarWinds Web Help Desk version 2026.1 and later.