SolarWinds has released security updates to patch critical authentication bypass and remote command execution vulnerabilities in its Web Help Desk IT help desk software. The authentication bypass security flaws (tracked as CVE-2025-40552 and CVE-2025-40554) patched today by SolarWinds were reported by watchTowr's Piotr Bazydlo and can be exploited by remote unauthenticated threat actors in low-complexity attacks. Bazydlo also found and reported a critical remote code execution (RCE) flaw (CVE-2025-40553) stemming from an untrusted data deserialization weakness that can enable attackers without privileges to run commands on vulnerable hosts. A second RCE vulnerability (CVE-2025-40551) reported by Horizon3.ai security researcher Jimi Sebree can also enable unauthenticated attackers to execute commands remotely. Today, SolarWinds also patched a high-severity hardcoded credentials vulnerability (CVE-2025-40537) discovered by Sebree that, under unspecified circumstances, could grant threat actors with low privileges unauthorized access to administrative functions. The company provides detailed instructions for upgrading vulnerable servers to Web Help Desk 2026.1, which addresses these security flaws. Admins are advised to patch their devices as soon as possible, as hackers have frequently exploited Web Help Desk security vulnerabilities in attacks. For instance, in September, SolarWinds addressed a second patch bypass (CVE-2025-26399) for a WHD RCE flaw that CISA flagged as activ...
SolarWinds warns of critical Web Help Desk RCE, auth bypass flaws
BleepingComputer
·Sergiu Gatlan
·Published Jan 28, 2026
·Updated
Affected Software
1 affected component
SolarWinds Web Help Desk>=2026.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses critical vulnerabilities in SolarWinds' Web Help Desk software, specifically authentication bypass and remote command execution flaws.
2
What security implications are discussed in the article?
The vulnerabilities could allow attackers to bypass authentication and execute commands remotely, posing significant risks to IT help desk operations.
3
What version of the affected software is mentioned?
The vulnerabilities affect SolarWinds Web Help Desk version 2026.1 and later.
4
How has SolarWinds addressed the vulnerabilities?
SolarWinds has released security updates to patch the critical authentication bypass and remote command execution vulnerabilities.
5
What should users of SolarWinds Web Help Desk do in response to this news?
Users should update their Web Help Desk software to the latest version to mitigate the identified security vulnerabilities.