• News/
  • https://www.bleepingcomputer.com/news/security/cisa-flags-critical-solarwinds-rce-flaw-as-actively-exploited/

CISA flags critical SolarWinds RCE flaw as exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 3, 2026
·
Updated

CISA has flagged a critical SolarWinds Web Help Desk vulnerability as actively exploited in attacks and ordered federal agencies to patch their systems within three days. Tracked as CVE-2025-40551, this security flaw stems from an untrusted data deserialization weakness discovered and reported by Horizon3.ai security researcher Jimi Sebree, which can allow unauthenticated attackers to gain remote command execution on unpatched devices. "SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution which would allow an attacker to run commands on the host machine," the company explained on January 28 when it released Web Help Desk 2026.1 to patch the vulnerability. The same day, SolarWinds also patched a high-severity hardcoded-credentials vulnerability (CVE-2025-40537) discovered by Sebree and two authentication-bypass security flaws (CVE-2025-40552 and CVE-2025-40554) reported by watchTowr's Piotr Bazydlo, all of them remotely exploitable. On Tuesday, CISA added CVE-2025-40551 to its catalog of flaws exploited in the wild and gave Federal Civilian Executive Branch (FCEB) agencies three days to secure their systems, as mandated by the Binding Operational Directive (BOD) 22-01, issued in November 2021. Although BOD 22-01 targets only federal agencies, CISA encouraged all network defenders, including those in the private sector, to patch their devices against ongoing CVE-2025-40551 attacks as so...

Read full article

Affected Software

1 affected component
SolarWinds Web Help Desk>=2026.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in SolarWinds Web Help Desk that is being actively exploited in attacks.

2

What security implications are discussed?

The article highlights the urgency for federal agencies to patch the vulnerability to prevent potential remote code execution attacks.

3

What is the CVE identifier for the SolarWinds vulnerability?

The vulnerability is tracked as CVE-2025-40551.

4

Which specific product is affected by this vulnerability?

The affected product is SolarWinds Web Help Desk.

5

What is the minimum version of the affected software?

The vulnerability affects SolarWinds Web Help Desk version 2026.1 and later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203